PT-2006-1140 · Python+2 · Email+3

Sven Hartge

·

Publicado

2006-03-31

·

Atualizado

2018-10-03

·

CVE-2006-0052

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Mailman versions 2.1.5 and earlier
Description: The issue allows remote attackers to cause a denial of service, specifically mailing list delivery failure, by sending a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary. This is related to the attachment scrubber (Scrubber.py) when using Python's library email module 2.5.
Recommendations: For Mailman versions 2.1.5 and earlier, consider updating to a newer version to resolve the issue. As a temporary workaround, restrict the handling of multipart MIME messages with unusual boundary formats to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0052
DSA-1027-1
RHSA-2006:0486
RHSA-2006_0486

Produtos afetados

Mailman
Python
Red Hat
Email