Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
A system hardening measure could be bypassed.. ========================================================================== Ubuntu Security Notice USN-8067-1 March 02, 2026 mailman vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 16.04 LTS Summary: A system hardening measure could be bypassed. Software Description: - mailman: Web-based mailing list manager Details: It was discovered that Mailman incorrectly handled CSRF tokens. A remote list member or moderator could possibly use their own token to craft an admin request CSRF attack and set a new admin password or make other changes. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS mailman 1:2.1.29-1ubuntu3.1+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS mailman 1:2.1.20-1ubuntu0.6+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8067-1 CVE-2021-44227 . A hardening measure in Ubuntu's Mailman can be bypassed, allowing unauthorized access. Update promptly to secure systems.. Mailman Update, Ubuntu Security, CSRF Exploit, System Hardening, Vulnerability Patch. . Severity: Important. LinuxSecurity.com Team
A flaw in Mailman 2.1.* allows a remote attacker to retrieve the mailman password of any subscriber by sending a carefully crafted email request to the mailman server. . Fedora Legacy Update Advisory Synopsis: Updated mailman resolves security vulnerability Advisory ID: FLSA:1734 Issue date: 2004-07-19 Product: Red Hat Linux Keywords: Bugfix Cross references: CVE Names: CAN-2004-0412 - ----------------------------------------------------------------------- - --------------------------------------------------------------------- 1. Topic: Updated mailman packages that fixes a remote security vulnerability are now available. 2. Relevent releases/architectures: Red Hat Linux 9 - i386 3. Problem description: Mailman is software to help manage email discussion lists, much like Majordomo and Smartmail. Unlike most similar products, Mailman gives each mailing list a webpage, and allows users to subscribe, unsubscribe, etc. over the Web. Even the list manager can administer his or her list entirely from the Web. Mailman also integrates most things people want to do with mailing lists, including archiving, mail news gateways, and so on. A flaw in Mailman 2.1.* allows a remote attacker to retrieve the mailman password of any subscriber by sending a carefully crafted email request to the mailman server. A simple patch is available and is fixed upstream in Mailman 2.1.5. All users are advised to upgrade to these updated packages, which contain a backported fix and are not vulnerable to this issue. Fedora Legacy would like to thank Marc Deslauriers for reporting this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installedwill be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via yum and apt. Many people find this an easier way to apply updates. To use yum issue: yum update or to use apt: apt-get update; apt-get upgrade This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. This assumes that you have yum or apt-get configured for obtaining Fedora Legacy content. Please visit for directions on how to configure yum and apt-get. 5. Bug IDs fixed: - 1734 - CAN-2004-0412 Mailman password retrieval 6. RPMs required: Red Hat Linux 9: SRPM: i386: 7. Verification: SHA1 sum Package Name - --------------------------------------------------------------------------- 4dee398d2d9b1d107850665f04c082073b4465a5 9/updates/SRPMS/mailman-2.1.1-7.legacy.src.rpm 66cbbfcf168869969b0aaa0298d3680c3b8e5a3c 9/updates/i386/mailman-2.1.1-7.legacy.i386.rpm These packages are GPG signed by Fedora Legacy for security. Our key is available from org/about/security.php You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the sha1sum with the following command: sha1sum 8. References: CVE -CVE-2004-0412 https://bugzilla.redhat.com/show_bug.cgi?id=123559 [Mailman-Announce] RELEASED Mailman 2.1.5 9. Contact: The Fedora Legacy security contact is . More project details at .org - --------------------------------------------------------------------- - -- Jesse Keating RHCE ( ) Fedora Legacy Team ( .org) GPG Public Key ( /jkeating.j2solutions.pub) Was I helpful? Let others know: Affero.net . A crucialupdate for the email server addresses a major security flaw that could allow unauthorized access to user passwords; all users are urgently encouraged to apply the patch immediately.. Mailman Security, Password Leak, Linux Update, Red Hat Advisory, Remote Access. . Severity: Critical. LinuxSecurity.com Team
Updated mailman packages are now available for Red Hat Secure Web Server3.2 (U.S.). These updates resolve a cross-site scripting vulnerabilitypresent in versions of Mailman prior to 2.0.11. . ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated mailman packages available Advisory ID: RHSA-2002:101-06 Issue date: 2002-05-22 Updated on: 2002-06-27 Product: Red Hat Secure Web Server Keywords: mailman cross-site scripting Cross references: RHSA-2002:099 RHSA-2002:100 Obsoletes: CVE Names: http://marc.theaimsgroup.com/?l=openssh-unix-dev&m=102510268109227 CAN-2002-0388 ---------------------------------------------------------------------1. Topic: Updated mailman packages are now available for Red Hat Secure Web Server 3.2 (U.S.). These updates resolve a cross-site scripting vulnerability present in versions of Mailman prior to 2.0.11. 2. Relevant releases/architectures: Red Hat Secure Web Server 3.2 - i386 3. Problem description: Two cross-site scripting vulnerabilities have been discovered in versions of Mailman prior to version 2.0.11. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactiveprocess that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Secure Web Server 3.2: i386: 7. Verification: MD5 sum Package Name --------------------------------------------------------------------------5b29f0e1a7af64d332c66c3a5b77dcff other_prod/secureweb/3.2/i386/mailman-2.0.11-0.6.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: [Mailman-Announce] RELEASED Mailman 2.0.11 CAN-2002-0388 CAN-2002-0388 Copyright(c) 2000, 2001, 2002 Red Hat, Inc. `. The latest updates to the mailman libraries tackle a critical cross-site scripting flaw in Red Hat Secure Web Server 3.2, thereby bolstering overall cybersecurity protocols.. Red Hat Secure Web Server, Mailman Update, Critical XSS Patch. . Severity: Critical. LinuxSecurity.com Team
Several vulnerabilities were discovered in Mailman, a web-based mailing list manager. An attacker could impersonate more privileged accounts through different vectors. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3049-1
An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: mailman:2.1 security update Advisory ID: RHSA-2021:5081-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:5081 Issue date: 2021-12-13 CVE Names: CVE-2021-44227 ==================================================================== 1. Summary: An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.1) - ppc64le, x86_64 3. Description: Mailman is a program used to help manage e-mail discussion lists. Security Fix(es): * mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover (CVE-2021-44227) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2026862 - CVE-2021-44227 mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover 6. Package List: Red Hat Enterprise Linux AppStream E4S(v. 8.1): Source: mailman-2.1.29-5.module+el8.1.0+13542+e9b93c88.src.rpm ppc64le: mailman-2.1.29-5.module+el8.1.0+13542+e9b93c88.ppc64le.rpm mailman-debuginfo-2.1.29-5.module+el8.1.0+13542+e9b93c88.ppc64le.rpm mailman-debugsource-2.1.29-5.module+el8.1.0+13542+e9b93c88.ppc64le.rpm x86_64: mailman-2.1.29-5.module+el8.1.0+13542+e9b93c88.x86_64.rpm mailman-debuginfo-2.1.29-5.module+el8.1.0+13542+e9b93c88.x86_64.rpm mailman-debugsource-2.1.29-5.module+el8.1.0+13542+e9b93c88.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-44227 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYbdOfNzjgjWX9erEAQhWoQ/8Cxrz5wjQt9nRTJErl3wAUsVNdt60Idtw F151HwxP27Ig3hWxPBRpV0RZvm0bSUGZuoyDWSNjaNDi9lt0uJKC0uk0VPG2ddcW L1cAp+CeF4G5zrIm8h+yEMu8tkk026ssxhc9EhfCkFR5rDzQZVD9EFssXGylI43D liiZmjxj6LKo5WS7I/xKLoizyW+jSeSYHdVXD/uDJMxBemrwPajYUJ0XyE17eYwm i4In/EOKOWbGIWMDov+IlRSVjvcWkHXhxLDQDKmQvxky3KPRWeTJSzCUMyB39pWh FFG+wFIEahdidEnWvoa9kW/JGQJ8W7nqpyVjEAwcEKrHncO7ifrWz/3kQHMWQeAA icR+XoIUfQUL4czDTtrSVrTzzSJsEPEoaITBsdMxhQGp0k3qYDXQ0UdEAD9x0bRt AvgliyH1QT5b+tbPfqjmhz+/jfaDma+gO6yPhrYPJItVo+7w855NixKrVCC4HL/T tdytscyqRz1SB/qiyP1S237a/iwfl8wkU6t0NAChoMGn2mBT6LF0UczWZMrriTgq G612mxfuA39lHRVAqIYa94q5A2IY2n0r3xEuEIw7Zs3MVkBcAolHayIjGgJaPl4x u5bTDI8COey3b08H3mNUPlDNmfZt0spNuyuRs//EYOwptxAZrZ1QV6qkFXyZVotG gh8YkH6IaBk=3hcq -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: mailman:2.1 security update Advisory ID: RHSA-2021:5080-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:5080 Issue date: 2021-12-13 CVE Names: CVE-2021-44227 ==================================================================== 1. Summary: An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v. 8.2) - aarch64, ppc64le, s390x, x86_64 3. Description: Mailman is a program used to help manage e-mail discussion lists. Security Fix(es): * mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover (CVE-2021-44227) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2026862 - CVE-2021-44227 mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.2): Source: mailman-2.1.29-6.module+el8.2.0+13543+86b2c701.src.rpm aarch64: mailman-2.1.29-6.module+el8.2.0+13543+86b2c701.aarch64.rpm mailman-debuginfo-2.1.29-6.module+el8.2.0+13543+86b2c701.aarch64.rpm mailman-debugsource-2.1.29-6.module+el8.2.0+13543+86b2c701.aarch64.rpm ppc64le: mailman-2.1.29-6.module+el8.2.0+13543+86b2c701.ppc64le.rpm mailman-debuginfo-2.1.29-6.module+el8.2.0+13543+86b2c701.ppc64le.rpm mailman-debugsource-2.1.29-6.module+el8.2.0+13543+86b2c701.ppc64le.rpm s390x: mailman-2.1.29-6.module+el8.2.0+13543+86b2c701.s390x.rpm mailman-debuginfo-2.1.29-6.module+el8.2.0+13543+86b2c701.s390x.rpm mailman-debugsource-2.1.29-6.module+el8.2.0+13543+86b2c701.s390x.rpm x86_64: mailman-2.1.29-6.module+el8.2.0+13543+86b2c701.x86_64.rpm mailman-debuginfo-2.1.29-6.module+el8.2.0+13543+86b2c701.x86_64.rpm mailman-debugsource-2.1.29-6.module+el8.2.0+13543+86b2c701.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-44227 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYbdOctzjgjWX9erEAQg6Ng/+MNYDR5KefRn68QosWvhOsTJw7ZeZxpD2 KGk2VSTT9MrMNSfd2uDuwVlMtyfCiFwO9+TrG2ou18K2ebZdbyCkwkYbWmk2j1xW GAMMWrzhlg2eBsiFTrDR03Hhm4P8kKYPeQymLk/z/I05csvvpSp/uDi1znwxiK6N JdDBE2N5x7RmvoLZ5RT7wY2Rh6D6Akn73Jrbsca9Rvxeu7fd16xQUNzbPvANSUIt BGCY0Ry2m9wZNvEGrdoD6ofO9WrAvTbJnnTcwX1L3Vtj0ykaELQCnJaEfzZ7wHPW qoKFxre5TPWHN+krtdTrkd/V2at/ANK7stKqPaBCpyDE5qARRgcSVs9nUt2DCdx1 lYC4bQbAO7AHQWkBE/Euyz6TN/hej96MvuUT68foM4taRVe/OEDxhi685jP2JWoF CyXBrOCROAiszUJfDbb8gP+P6386qaED0pTh6o+RGaIV4FFBOaEBXxGkU93sGcvY ATA8GfiU7Hx5u4URWrLjB4xcQbjo28EFY4Ky896re2kR3kw80irEanFWqupb0zE3 5P+arSFV3EHVJf5fse7m4VagctuQ8yn4HwlW6kUAHwBGVTIOJGjq/JWVkV1xGe3L L44SbjRjynwA8Dpeb2k990GvBa/xPg1DCkS+hmpNi2whm/fwtB19yOSgr8EkWO7N 6u77NOONp3M=6HtR -----END PGP SIGNATURE----- -- RHSA-announce mailing list
A system hardening measure could be bypassed.. =========================================================================Ubuntu Security Notice USN-5180-1 December 07, 2021 mailman vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: A system hardening measure could be bypassed. Software Description: - mailman: Web-based mailing list manager Details: It was discovered that Mailman incorrectly handled CSRF tokens. A remote list member or moderator could possibly use their own token to craft an admin request CSRF attack and set a new admin password or make other changes. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: mailman 1:2.1.26-1ubuntu0.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5180-1 CVE-2021-44227 Package Information: https://launchpad.net/ubuntu/+source/mailman/1:2.1.26-1ubuntu0.6 . Urgent patch issued for Mailman on Ubuntu 20.04 LTS, addressing severe risks of XSS exploits.. mailman vulnerability, Ubuntu security, system hardening, CSRF exploit, update instructions. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2021-4913 https://linux.oracle.com/errata/ELSA-2021-4913.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: mailman-2.1.15-30.el7_9.2.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/mailman-2.1.15-30.el7_9.2.src.rpm Related CVEs: CVE-2016-6893 CVE-2021-42097 CVE-2021-44227 Description of changes: [3:2.1.15-30.2] - Fix for CVE-2021-44227 - Resolves: #2026866 [3:2.1.15-30.1] - Fix for CVE-2016-6893 - Fix for CVE-2021-42097 - Resolves: #2024884, #2020688 _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.