Description
The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
Affected products
- gnu / Mailman1.0 – 1.0
- gnu / Mailman1.1 – 1.1
- gnu / Mailman2.0 – 2.0
- gnu / Mailman2.0 – 2.0
- gnu / Mailman2.0 – 2.0
- gnu / Mailman2.0 – 2.0
- gnu / Mailman2.0.1 – 2.0.1
- gnu / Mailman2.0.2 – 2.0.2
- gnu / Mailman2.0.3 – 2.0.3
- gnu / Mailman2.0.4 – 2.0.4
- gnu / Mailman2.0.5 – 2.0.5
- gnu / Mailman2.0.6 – 2.0.6
- gnu / Mailman2.0.7 – 2.0.7
- gnu / Mailman2.0.8 – 2.0.8
- gnu / Mailman2.0.9 – 2.0.9
- gnu / Mailman2.0.10 – 2.0.10
- gnu / Mailman2.0.11 – 2.0.11
- gnu / Mailman2.0.12 – 2.0.12
- gnu / Mailman2.0.13 – 2.0.13
- gnu / Mailman2.1 – 2.1
- gnu / Mailman2.1.1 – 2.1.1
- gnu / Mailman2.1.2 – 2.1.2
- gnu / Mailman2.1.3 – 2.1.3
- gnu / Mailman2.1.4 – 2.1.4
- gnu / Mailman2.1b1 – 2.1b1
References
- MAILING_LISThttp://marc.info/?l=bugtraq&m=110549296126351&w=2
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/18857
- VENDOR_ADVISORYhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286796
- MAILING_LISThttp://www.novell.com/linux/security/advisories/2005_07_mailman.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/13603/