ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Mailman flaw gives away passwords

Published: 11 Feb 2005 09:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A previously unknown vulnerability in Mailman, a popular open source program for managing mailing lists, has led to the theft of the password file for a well-known security discussion group.

The theft, discovered this week and reported in an announcement to the Full Disclosure security mailing list on Wednesday, casts uncertainty on the security of other discussion groups that use the open source Mailman package. By specially crafting a Web address, an attacker can obtain the password for every member of a discussion group.

"Anyone with a Web browser can download a file off a vulnerable system -- it's [easy to do]," said John Cartwright, co-founder and manager of the Full Disclosure mailing list. The attack, known as a remote directory traversal exploit, occurred on 2 January, according to Cartwright's investigation. "As far as our server goes, there is no evidence that any other files were accessed using this flaw."

The flaw could have far-reaching consequences because some mailing list subscribers change their access code to a password that they reuse elsewhere. Since Mailman uses subscribers' email as their user name, people who reuse passwords could put other accounts in jeopardy.

Servers that run Apache 2.0 and Mailman are suspected to be immune to exploitation of the vulnerability, according to a security advisory on the Mailman Web site.

"In any event, the safest approach is to assume the worst, and it is recommended that you apply this Mailman patch as soon as possible," the advisory stated.

The Full Disclosure discussion list had used Mailman running on Apache 1.3, a vulnerable configuration.

Companies and projects that distributed Mailman as part of their Linux distribution have already started releasing fixes for the problem. Debian, Ubuntu and Gentoo Linux have released advisories citing the problem and offering patches.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
46 out of 81 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Sentry Posts Blog

Toshiba touts Quantum Key Distribution

Toshiba research scientists have developed a method of distributing quantum keys more efficiently, the company has claimed in a statement: "[Quantum Key Distribution -- ] QKD --... More

Post a comment

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment