CVE-2003-0991
published 2004-03-03CVE-2003-0991: Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail…
PriorityP415medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.94%
78.0th percentile
Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| sgi | propack | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2004-02-09·CVSS 5.0
CVE-2003-0991 [MEDIUM] security flaw
security flaw
Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.
GHSA
GHSA-5vf7-m49c-hv97: Unknown vulnerability in the mail command handler in Mailman before 2
ghsa_unreviewed·2022-05-03
CVE-2003-0991 [MEDIUM] GHSA-5vf7-m49c-hv97: Unknown vulnerability in the mail command handler in Mailman before 2
Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2003-0991 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2003-0991 [MEDIUM] CVE-2003-0991 security flaw
CVE-2003-0991 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.
Bugzilla
CAN-2005-0202 Mailman directory traversal
bugzilla·2005-02-10
[MEDIUM] CAN-2005-0202 Mailman directory traversal
CAN-2005-0202 Mailman directory traversal
Created an SRPM using patch from RHEL3 and SRPM from FC1.
http://www.cs.ucsb.edu/~jeff/mailman-2.1.5-7.legacy.src.rpm
Feel free to use/rebuild as necesary.
------- Additional Comments From [email protected] 2005-02-10 09:27:32 ----
QA for RPM in comment 1:
6e4d02c20ca4f3093a4b1ba6b82f3b1533ccfeab mailman-2.1.5-7.legacy.src.rpm
- spec change good
- patch good
- sources good
- no other changes
PUBLISH fc1
------- Additional Comments From [email protected] 2005-02-10 11:50:05 ----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Whoops, guess I should have gpg signed my first message
and added the shasum... well, I'll get used to this eventually :)
I've also taken the most recent legacy mailman release for RH9 and rebuilt
it with the same pat
ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000842http://mail.python.org/pipermail/mailman-announce/2004-February/000067.htmlhttp://www.debian.org/security/2004/dsa-436http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:013http://www.redhat.com/support/errata/RHSA-2004-019.htmlhttp://www.securityfocus.com/bid/9620https://exchange.xforce.ibmcloud.com/vulnerabilities/15106ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000842http://mail.python.org/pipermail/mailman-announce/2004-February/000067.htmlhttp://www.debian.org/security/2004/dsa-436http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:013http://www.redhat.com/support/errata/RHSA-2004-019.htmlhttp://www.securityfocus.com/bid/9620https://exchange.xforce.ibmcloud.com/vulnerabilities/15106
2004-03-03
Published