It is possible to mailbomb a member of a list with a private roster by repeatedly posting the subscribe form.

Bug #1883017 reported by Mark Sapiro
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
GNU Mailman
Fix Released
Low
Mark Sapiro

Bug Description

On a list with a private roster, an attempt to subscribe an address which is already a member results in a warning notice sent to the target address. To prevent using this to mailbomb a list member, there is a new WARN_MEMBER_OF_SUBSCRIBE setting that can be set to No to suppress the warning.

Related branches

Mark Sapiro (msapiro)
description: updated
Mark Sapiro (msapiro)
Changed in mailman:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.