I have a working install of Mailman 2.15 on FreeBSD. I installed it from the ports collection. You have to run the CGI scirpts under the apache account otherwise suexec will complain.
I don't think this is security issue unless you have private (member_only) archives.