Mailman: Member password disclosure vulnerability — GLSA 200406-04 Mailman contains a bug allowing 3rd parties to retrieve member passwords. Affected packages Package net-mail/mailman on all architectures Affected versions < 2.1.5 Unaffected versions >= 2.1.5 Background Mailman is a python-based mailing list server with an extensive web interface. Description Mailman contains an unspecified vulnerability in the handling of request emails. Impact By sending a carefully crafted email request to the mailman server an attacker could obtain member passwords. Workaround There is no known workaround at this time. Resolution All users of Mailman should upgrade to the latest stable version: # emerge sync # emerge -pv ">=net-mail/mailman-2.1.5" # emerge ">=net-mail/mailman-2.1.5" References Mailman 2.1.5 Release Announcement CAN-2004-0412