Debian Security Advisory: Package: majordomo | Linux Today

Debian Security Advisory: Package: majordomo

Written By
Web Webster
Web Webster
Jun 4, 2000

Date: Sat, 3 Jun 2000 21:18:29 +0200
From: Wichert Akkerman wichert@cistron.nl
To: debian-security-announce@lists.debian.org
Subject: [SECURITY] Majordomo will be removed


Debian Security Advisory                             security@debian.org
http://www.debian.org/security/                         Wichert Akkerman
June  3, 2000

Package        : majordomo
Problem type   : local exploit
Debian-specific: no

The majordomo package as shipped in the non-free section
accompanying Debian GNU/Linux 2.1/slink allows any local user to
trick majordomo into executing arbitrary code or to create or write
files as the majordomo user anywhere on the filesystem.

This is a documented issue and the advised work around it to
either have no untrusted users on a system running majordomo or to
use a setuid wrapper that the MTA delivery agent can run.
suboptimal solution.

We feel that those options are not a good solution, but
unfortunately the majordomo license does not allow us to fix these
problems and distribute a fixed version. As a result we have
decided to remove majordomo from our archives.

If you are using majordomo we recommend that you replace it with
one of the many other mailing-list tools available such as fml,
mailman or smartlist.

– —


For apt-get: deb http://security.debian.org/
stable updates
For dpkg-ftp: ftp://security.debian.org/debian-security
dists/stable/updates

Mailing list: debian-security-announce@lists.debian.org

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.