CVE-2005-4153
published 2005-12-11CVE-2005-4153: Mailman 2.1.4 through 2.1.6 allows remote attackers to cause a denial of service via a message that causes the server to "fail with an Overflow on bad date…
PriorityP426high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.07%
86.3th percentile
Mailman 2.1.4 through 2.1.6 allows remote attackers to cause a denial of service via a message that causes the server to "fail with an Overflow on bad date data in a processed message," a different vulnerability than CVE-2005-3573.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9hr9-wg7q-ffxj: Mailman 2
ghsa_unreviewed·2022-05-03·CVSS 5.0
CVE-2005-4153 [MEDIUM] GHSA-9hr9-wg7q-ffxj: Mailman 2
Mailman 2.1.4 through 2.1.6 allows remote attackers to cause a denial of service via a message that causes the server to "fail with an Overflow on bad date data in a processed message," a different vulnerability than CVE-2005-3573.
Ubuntu
mailman vulnerabilities
vendor_ubuntu·2006-01-16·CVSS 5.0
CVE-2005-4153 [MEDIUM] mailman vulnerabilities
Title: mailman vulnerabilities
Summary: mailman vulnerabilities
Aliet Santiesteban Sifontes discovered a remote Denial of Service
vulnerability in the attachment handler. An email with an attachment
whose filename contained invalid UTF-8 characters caused mailman to
crash. (CVE-2005-3573)
Mailman did not sufficiently verify the validity of email dates. Very
large numbers in dates caused mailman to crash. (CVE-2005-4153)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-09-01·CVSS 5.0
CVE-2005-4153 [MEDIUM] security flaw
security flaw
Mailman 2.1.4 through 2.1.6 allows remote attackers to cause a denial of service via a message that causes the server to "fail with an Overflow on bad date data in a processed message," a different vulnerability than CVE-2005-3573.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-4153 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2005-4153 [MEDIUM] CVE-2005-4153 security flaw
CVE-2005-4153 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Mailman 2.1.4 through 2.1.6 allows remote attackers to cause a denial of service via a message that causes the server to "fail with an Overflow on bad date data in a processed message," a different vulnerability than CVE-2005-3573.
Bugzilla
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
bugzilla·2006-10-20·CVSS 5.0
CVE-2006-4624 [MEDIUM] CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
+++ This bug was initially created as a clone of Bug #209891 +++
Cloning for FC3.
+++ This bug was initially created as a clone of Bug #206607 +++
FC6 needs mailman 2.1.9 to correct CVE-2006-4624, CVE-2006-3636, CVE-2006-2941
This bug is for FC3 and FC4. Upgrading to mailman 2.1.9 will correct these
vulnerabilities.
Discussion:
Oh okay. I guess I thought it was simpler to track a single issue in
just one bug report, but I guess splitting them out may help ... ? I
hope it does.
---
The current version of the .src.rpm is
mailman-2.1.5-32.fc3.src.rpm
at
---
Can someone check the src.rpm I made with the lateest mailman from legacy and
the patches from RHEL?
http://bugs.unl.edu.ar/~martin/mailman-2.1.5-33.fc3.legacy
Bugzilla
CVE-2006-0052 Mailman DoS, CVE-2006-1712 Mailman cross site scripting bug and CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153); also CAN-2004-1177 Cross-site scripting (XSS) vulnerability
bugzilla·2006-06-02·CVSS 5.0
CVE-2006-0052 [MEDIUM] CVE-2006-0052 Mailman DoS, CVE-2006-1712 Mailman cross site scripting bug and CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153); also CAN-2004-1177 Cross-site scripting (XSS) vulnerability
CVE-2006-0052 Mailman DoS, CVE-2006-1712 Mailman cross site scripting bug and CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153); also CAN-2004-1177 Cross-site scripting (XSS) vulnerability
Mailman DoS allows remote attackers to cause a denial of service by using
multipart MIME message with a single part MIME message.
Mailman cross site scripting bug allows remote attackers to inject arbitrary web
script in the form ofaction argument.
In Mailman Denial of Service application crash and server message "fail with an
Overflow on bad date data in a processed message".
http://www.redhat.com/archives/fedora-test-list/2006-May/msg00131.html
http://www.redhat.com/archives/fedora-package-announce/2006-May/msg00134.htm
http://www.redhat.com/archives/fedora-package-announce/2006-May/msg00135.
Bugzilla
CVE-2005-4153 Mailman DOS
bugzilla·2005-12-19·CVSS 5.0
CVE-2005-4153 [MEDIUM] CVE-2005-4153 Mailman DOS
CVE-2005-4153 Mailman DOS
From CVE:
Mailman 2.1.4 through 2.1.6 allows remote attackers to cause a denial of service
via a message that causes the server to "fail with an Overflow on bad date data
in a processed message," a different vulnerability than CVE-2005-3573.
This bug report has more details including a patch:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=326024
Seems to have been public since 20050901 but the bug report doesn't mention in
Debian submitted this upstream.
Affects: RHEL4, RHEL3
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may re
Bugzilla
CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153)
bugzilla·2005-11-14·CVSS 5.0
CVE-2005-3573 [MEDIUM] CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153)
CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153)
Mailman Denial of Service
A message with a malformed Content-Disposition: headers can crash
mailman and prevent a list from working. The bad file will not affect
all lists hosted on the machine, only the list which receives the
malicious message.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=327732
This issue also affects FC3
Discussion:
Also another DoS based on integer overflow of year in header:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=326024
CVE-2005-4153
---
Please test
http://www.redhat.com/archives/fedora-test-list/2006-May/msg00131.html
---
I am suspecting that this bug report is related to the mailman package that
was released in FEDORA-2006-534, mailman-2.1.8-0.FC4.1,
?
If so, should this bug be closed
ftp://patches.sgi.com/support/free/security/advisories/20060401-01-Uhttp://secunia.com/advisories/18449http://secunia.com/advisories/18456http://secunia.com/advisories/18612http://secunia.com/advisories/19167http://secunia.com/advisories/19196http://secunia.com/advisories/19532http://www.debian.org/security/2006/dsa-955http://www.osvdb.org/21723http://www.redhat.com/support/errata/RHSA-2006-0204.htmlhttp://www.securityfocus.com/bid/16248http://www.trustix.org/errata/2006/0012/http://www.ubuntu.com/usn/usn-242-1http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:222https://exchange.xforce.ibmcloud.com/vulnerabilities/23139https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10660ftp://patches.sgi.com/support/free/security/advisories/20060401-01-Uhttp://secunia.com/advisories/18449http://secunia.com/advisories/18456http://secunia.com/advisories/18612http://secunia.com/advisories/19167http://secunia.com/advisories/19196http://secunia.com/advisories/19532http://www.debian.org/security/2006/dsa-955http://www.osvdb.org/21723http://www.redhat.com/support/errata/RHSA-2006-0204.htmlhttp://www.securityfocus.com/bid/16248http://www.trustix.org/errata/2006/0012/http://www.ubuntu.com/usn/usn-242-1http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:222https://exchange.xforce.ibmcloud.com/vulnerabilities/23139https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10660
2005-12-11
Published