Описание
Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.
Mailman versions 2.1.5 and below allow for user passwords to be obtained via a crafted email which can compromise data confidentiality.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | mailman | Not affected | ||
Red Hat Enterprise Linux 7 | mailman | Not affected | ||
Red Hat Enterprise Linux 8 | mailman:2.1/mailman | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2011228mailman: password stealing via a crafted email request
EPSS
Процентиль: 85%
0.0264
Низкий
6.5 Medium
CVSS3
Связанные уязвимости
ubuntu
почти 21 год назад
Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.
nvd
почти 21 год назад
Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.
debian
почти 21 год назад
Mailman before 2.1.5 allows remote attackers to obtain user passwords ...
EPSS
Процентиль: 85%
0.0264
Низкий
6.5 Medium
CVSS3