USN-78-1: Mailman vulnerability

10 February 2005

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 4.10

An path traversal vulnerability has been discovered in the “private” module of Mailman. A flawed path sanitation algorithm allowed the construction of URLS to arbitrary files readable by Mailman. This allowed a remote attacker to retrieve configuration and password databases, private list archives, and other files.

