PT-2006-5409 · Gnu+1 · Mailman+1

Moritz Naumann

·

Publicado

2006-09-07

·

Atualizado

2018-10-17

·

CVE-2006-4624

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mailman versions prior to 2.1.9rc1
Description The issue is related to a CRLF injection vulnerability in the Utils.py file. This vulnerability allows remote attackers to inject CRLF sequences into the URI, potentially spoofing messages in the error log. Attackers may use this to trick administrators into visiting malicious URLs.
Recommendations For versions prior to 2.1.9rc1, update to version 2.1.9rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to the error log to minimize the risk of exploitation. Avoid using URLs with CRLF sequences in the affected Mailman version until the issue is resolved.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-4624
DSA-1188-1
RHSA-2007:0779
RHSA-2007_0779

Produtos afetados

Mailman
Red Hat