From b2a8ab50ca10ff83839cd876f7f9a6495c33293c Mon Sep 17 00:00:00 2001
From: bwarsaw <>
Date: Thu, 10 Feb 2005 14:10:10 +0000
Subject: Add information regarding CAN-2005-0202 vulnerability, with patches
and recommendations. Also include reference to a new email address folks can
use to contact the Mailman security response team.
---
admin/www/security.html | 197 ++++++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 197 insertions(+)
create mode 100644 admin/www/security.html
(limited to 'admin/www/security.html')
diff --git a/admin/www/security.html b/admin/www/security.html
new file mode 100644
index 00000000..4d7c40cb
--- /dev/null
+++ b/admin/www/security.html
@@ -0,0 +1,197 @@
+
+
+
+
+
+
+
+
+
+Mailman security issues
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ |
+ |
+
+
+
+
+
+
+ |
+
+
+
+
+ |
+
+
+
+Mailman security issues
+
+The GNU Mailman developers take security very seriously. All Mailman security
+concerns should be emailed to
+mailman-security@python.org. This is
+a closed list that reaches the core Mailman developers.
+
+Known issues and fixes
+
+
+- CAN-2005-0202 -- This is a very serious issue affecting
+the Mailman 2.1 serious up to and including version 2.1.5. Mailman 2.1.6 is
+not vulnerable. This issue can allow for the leakage of member passwords.
+
+
The extent of your exposure to this vulnerability depends on factors such
+as which version of Apache you are running and how you have it configured. We
+do not currently know the exact combination that enables the hole, although we
+currently believe that Apache 2.0 sites are not vulnerable and that that many
+if not most Apache 1.3 sites are vulnerable. In any event, the safest
+approach is to assume the worst and it is recommended that you apply
+this Mailman patch as soon as possible.
+
+ For additional piece of mind, it is
+recommended that you regenerate your list member passwords using
+the Mailman 2.1.6 reset_pw.py script. Put this file
+in your Mailman installation's bin directory. After running the script, you
+might also want to manually run the cron/mailpasswds script so that your users
+will be informed of their new passwords.
+
+
+
+ |
+
+
+
--
cgit v1.2.3