Vulnerability Name: | CVE-2002-0389 (CCN-8874) | ||||||||||||||||||||
Assigned: | 2002-04-17 | ||||||||||||||||||||
Published: | 2002-04-17 | ||||||||||||||||||||
Updated: | 2016-12-28 | ||||||||||||||||||||
Summary: | Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives. | ||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2002-0389 Source: BUGTRAQ Type: UNKNOWN 20020417 Mailman/Pipermail private mailing list/local user vulnerability Source: CCN Type: BugTraq Mailing List, 2002-04-17 4:20:09 Mailman/Pipermail private mailing list/local user vulnerability Source: REDHAT Type: UNKNOWN RHSA-2015:1417 Source: CCN Type: SquirrelMail Bug Tracker Bug #474616 Pipermail permissions problem Source: MISC Type: UNKNOWN http://sourceforge.net/tracker/?func=detail&atid=100103&aid=474616&group_id=103 Source: XF Type: UNKNOWN pipermail-view-archives(8874) Source: CCN Type: OSVDB ID: 5309 Mailman Pipermail Predictable File Name Private Mail Disclosure Source: BID Type: UNKNOWN 4538 Source: CCN Type: BID-4538 Pipermail/Mailman Insecure Archives Permissions Vulnerability Source: XF Type: UNKNOWN pipermail-view-archives(8874) | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |