Vulnerability in Mailman mail-list software leaks passwords


scan pc for spyware or adware free


Vulnerability in Mailman mail-list software leaks passwords

A previously unknown vulnerability in Mailman's mail-list, a popular 
open-source program for managing mailing lists, has led to the theft 
of the password file for a well-known security discussion group.

The theft, discovered this week and reported in an announcement to the
Full Disclosure security mailing list on Wednesday, casts uncertainty
on the security of other discussion groups that use the open-source
Mailman package. By specially crafting a Web address, an attacker can
obtain the password for every member of a discussion group.

"Anyone with a Web browser can download a file off a vulnerable
system--it's (easy to do)," said John Cartwright, co-founder and
manager of the Full Disclosure mailing list. The attack, known as a
remote directory traversal exploit, occurred on Jan. 2, according to
Cartwright's investigation. "As far as our server goes, there is no
evidence that any other files were accessed using this flaw."

The flaw could have far-reaching consequences because some mailing
list subscribers change their access code to a password that they
reuse elsewhere. Since Mailman uses subscribers' e-mail as their user
name, people who reuse passwords could put other accounts in jeopardy.

Servers that run Apache 2.0 and Mailman are suspected to be immune to
exploitation of the vulnerability, according to a security advisory on
the Mailman Web site.

"In any event, the safest approach is to assume the worst, and it is
recommended that you apply this Mailman patch as soon as possible,"  
the advisory stated.

The Full Disclosure discussion list had used Mailman running on Apache
1.3, a vulnerable configuration.

Companies and projects that distributed Mailman as part of their Linux
distribution have already started releasing fixes for the problem.  
Debian, Ubuntu and Gentoo Linux have released advisories citing the
problem and offering patches.



Internet Security News Home

 

WorldsLargestNetwork.com




Scan Your PC for Spyware Free

PC Speed Boost

Create Website Easily

Computer Monitoring Software

Internet Education

Anti Spy Software

Stop Pop Ups

Pop-up Eliminator

Adware Removal

Computer Virus Software

Free Scan Spyware Remover

IT Training

Security Software

Security Solutions

Software Protection

Speed Up PC

Virus Protection

Web Safety

Adware Remover and Spyware Protection

Animated Desktop Characters

Anti Virus Software

Audioexam Study Guides in Mp3 Format

Internet Privacy

Detection Connection

Investigate Anyone or Anything

Password Protection Software

Securing Privacy

Spyware Remover






Best of the Web 1 | Best of the Web 2 | Best of the Web 3 | Best of the Web 4


Worlds Largest Network

Active © 2006; WorldsLargestNetwork.com ; Rights Reserved