Описание
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
It was found that mailman stored private email messages in a world-readable directory. A local user could use this flaw to read private mailing list archives.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 4 | mailman | Will not fix | ||
Red Hat Enterprise Linux 5 | mailman | Will not fix | ||
Red Hat Enterprise Linux 6 | mailman | Fixed | RHSA-2015:1417 | 20.07.2015 |
Показывать по
Дополнительная информация
Статус:
EPSS
2.1 Low
CVSS2
Связанные уязвимости
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
ELSA-2015-1417: mailman security and bug fix update (MODERATE)
EPSS
2.1 Low
CVSS2