[ mailman-Patches-885098 ] Information leak when issuing a subscribe request

SourceForge.net noreply at sourceforge.net
Mon Jan 26 17:13:35 EST 2004


Patches item #885098, was opened at 2004-01-26 22:13
Message generated for change (Tracker Item Submitted) made by Item Submitter
You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=300103&aid=885098&group_id=103

Category: list administration
Group: Mailman 2.1
Status: Open
Resolution: None
Priority: 5
Submitted By: Tom Coerkamp (tomcoerkamp)
Assigned to: Nobody/Anonymous (nobody)
Summary: Information leak when issuing a subscribe request

Initial Comment:
When a request to listname-request is sent with a
command "subscribe address=foo at bar.com", the errors are
returned to the sender of the command rather than the
address it relates to.

If the subscriber is already subscribed to the list, an
error message is returned to the sender of the request
with that error, thus informing the sender of the
request the subscription status of the requested email
address.  

Similarly if the subscription request is successful and
no confirmation is required, the sender of the request
is notified of this.



----------------------------------------------------------------------

You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=300103&aid=885098&group_id=103



More information about the Mailman-coders mailing list