• Bug#264916: mailman: login fails when user missing (pipermail private a

    From Patrik Wallstrom@1:229/2 to All on Wed Aug 11 00:20:07 2004
    From: [email protected]

    Package: mailman
    Version: 2.1.4-5
    Severity: important

    When a user is logging in for the private mail archives, and the
    username is missing from the list, mailman fails with an error (a python
    error) stating that the user is missing. This might be considered a serious security problem.

    -- System Information:
    Debian Release: 3.1
    APT prefers unstable
    APT policy: (990, 'unstable')
    Architecture: i386 (i686)
    Kernel: Linux 2.6.5
    Locale: LANG=C, LC_CTYPE=sv_SE

    Versions of packages mailman depends on:
    ii apache [httpd] 1.3.31-3 Versatile, high-performance HTTP s ii cron 3.0pl1-86 management of regular background p ii debconf 1.4.30 Debian configuration management sy ii libc6 2.3.2.ds1-15 GNU C Library: Shared libraries an ii logrotate 3.7-2 Log rotation utility
    ii postfix [mail-transport-age 2.1.4-4 A high-performance mail transport ii pwgen 2.03-1 Automatic Password generation
    ii python 2.3.4-1 An interactive high-level object-o ii ucf 1.07 Update Configuration File: preserv

    -- debconf information:
    * mailman/site_languages: sv, en
    * mailman/used_languages: en sv
    * mailman/create_site_list:
    * mailman/default_server_language: en
    mailman/gate_news: false


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • From Tollef Fog Heen@1:229/2 to All on Wed Aug 18 19:40:08 2004
    From: [email protected]

    tags 264916 + unreproducible
    severity 264916 normal
    thanks

    * Patrik Wallstrom

    | When a user is logging in for the private mail archives, and the
    | username is missing from the list, mailman fails with an error (a python
    | error) stating that the user is missing. This might be considered a serious
    | security problem.

    I am not able to reproduce this. Could you please provide me with the
    exact error you get?

    --
    Tollef Fog Heen ,''`. UNIX is user friendly, it's just picky about who its friends are : :' :
    `. `'
    `-


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)