The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.
| Software | From | Fixed in |
|---|---|---|
| gnu / mailman | 2.0-beta3 | 2.0-beta3.x |
| conectiva / linux | 4.2 | 4.2.x |
| conectiva / linux | 4.1 | 4.1.x |
| gnu / mailman | 2.0-beta4 | 2.0-beta4.x |
| conectiva / linux | 5.1 | 5.1.x |
| conectiva / linux | 5.0 | 5.0.x |
| redhat / linux | - | - |