GNU Mailman Empty Password Blank Salt Vulnerability
BID:3295
Info
GNU Mailman Empty Password Blank Salt Vulnerability
| Bugtraq ID: | 3295 |
| Class: | Environment Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2001 12:00AM |
| Updated: | Sep 05 2001 12:00AM |
| Credit: | This vulnerability was announced to Bugtraq in a Conectiva Security Advisory on September 5, 2001. |
| Vulnerable: |
GNU Mailman 2.0.5 GNU Mailman 2.0.4 GNU Mailman 2.0.3 GNU Mailman 2.0.2 GNU Mailman 2.0.1 GNU Mailman 2.0 |
| Not Vulnerable: |
GNU Mailman 2.0.6 |
Discussion
GNU Mailman Empty Password Blank Salt Vulnerability
GNU Mailman is a freely available, open source mailing list manager written in Python, and maintained by public domain.
A problem has been discovered in GNU Mailman that can allow users arbitrary access to accounts. When a password file has been created, but left blank, it is possible for a remote user to gain access to a user account as by entering an arbitrary password of any type. This is due to a bug in the crypt function, which upon receiving a blank salt, will return a blank hash.
GNU Mailman is a freely available, open source mailing list manager written in Python, and maintained by public domain.
A problem has been discovered in GNU Mailman that can allow users arbitrary access to accounts. When a password file has been created, but left blank, it is possible for a remote user to gain access to a user account as by entering an arbitrary password of any type. This is due to a bug in the crypt function, which upon receiving a blank salt, will return a blank hash.
Exploit / POC
GNU Mailman Empty Password Blank Salt Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
GNU Mailman Empty Password Blank Salt Vulnerability
Solution:
Updates available:
GNU Mailman 2.0
GNU Mailman 2.0.1
GNU Mailman 2.0.2
GNU Mailman 2.0.3
GNU Mailman 2.0.4
GNU Mailman 2.0.5
Solution:
Updates available:
GNU Mailman 2.0
-
GNU Mailman 2.0.6
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.6.tgz
GNU Mailman 2.0.1
-
GNU Mailman 2.0.6
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.6.tgz
GNU Mailman 2.0.2
-
GNU Mailman 2.0.6
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.6.tgz
GNU Mailman 2.0.3
-
GNU Mailman 2.0.6
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.6.tgz
GNU Mailman 2.0.4
-
GNU Mailman 2.0.6
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.6.tgz
GNU Mailman 2.0.5
-
Conectiva 4.1 i386 mailman-2.0.6-1U41_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.1/i386/mailman-2.0.6-1U41_1cl.i3 86.rpm -
Conectiva 4.2 i386 mailman-2.0.6-1U42_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.2/i386/mailman-2.0.6-1U42_1cl.i3 86.rpm -
Conectiva 5.0 i386 mailman-2.0.6-1U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/mailman-2.0.6-1U50_1cl.i3 86.rpm -
Conectiva 5.1 i386 mailman-2.0.6-1U51_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/mailman-2.0.6-1U51_1cl.i3 86.rpm -
Conectiva 6.0 i386 mailman-2.0.6-1U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/mailman-2.0.6-1U60_1cl.i3 86.rpm -
Conectiva 7.0 i386 mailman-2.0.6-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/mailman-2.0.6-1U70_1cl.i3 86.rpm -
GNU Mailman 2.0.6
ftp://ftp.gnu.org/gnu/mailman/mailman-2.0.6.tgz