CVE-2006-0052
published 2006-03-31CVE-2006-0052: The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of…
PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.64%
84.0th percentile
The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
mailman vulnerability
vendor_ubuntu·2006-04-04
CVE-2006-0052 mailman vulnerability
Title: mailman vulnerability
Summary: mailman vulnerability
A remote Denial of Service vulnerability was discovered in the decoder
for multipart messages. Certain parts of type "message/delivery-status"
or parts containing only two blank lines triggered an exception. An
attacker could exploit this to crash Mailman by sending a
specially crafted email to a mailing list.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-06-06·CVSS 5.0
CVE-2006-0052 [MEDIUM] security flaw
security flaw
The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.
GHSA
GHSA-f27j-9fv2-5hrg: The attachment scrubber (Scrubber
ghsa_unreviewed·2022-05-03
CVE-2006-0052 [MEDIUM] GHSA-f27j-9fv2-5hrg: The attachment scrubber (Scrubber
The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-0052 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2006-0052 [MEDIUM] CVE-2006-0052 security flaw
CVE-2006-0052 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.
Bugzilla
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
bugzilla·2006-10-20·CVSS 5.0
CVE-2006-4624 [MEDIUM] CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
+++ This bug was initially created as a clone of Bug #209891 +++
Cloning for FC3.
+++ This bug was initially created as a clone of Bug #206607 +++
FC6 needs mailman 2.1.9 to correct CVE-2006-4624, CVE-2006-3636, CVE-2006-2941
This bug is for FC3 and FC4. Upgrading to mailman 2.1.9 will correct these
vulnerabilities.
Discussion:
Oh okay. I guess I thought it was simpler to track a single issue in
just one bug report, but I guess splitting them out may help ... ? I
hope it does.
---
The current version of the .src.rpm is
mailman-2.1.5-32.fc3.src.rpm
at
---
Can someone check the src.rpm I made with the lateest mailman from legacy and
the patches from RHEL?
http://bugs.unl.edu.ar/~martin/mailman-2.1.5-33.fc3.legacy
Bugzilla
CVE-2006-0052 Mailman DoS, CVE-2006-1712 Mailman cross site scripting bug and CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153); also CAN-2004-1177 Cross-site scripting (XSS) vulnerability
bugzilla·2006-06-02·CVSS 5.0
CVE-2006-0052 [MEDIUM] CVE-2006-0052 Mailman DoS, CVE-2006-1712 Mailman cross site scripting bug and CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153); also CAN-2004-1177 Cross-site scripting (XSS) vulnerability
CVE-2006-0052 Mailman DoS, CVE-2006-1712 Mailman cross site scripting bug and CVE-2005-3573 Mailman Denial of Service (CVE-2005-4153); also CAN-2004-1177 Cross-site scripting (XSS) vulnerability
Mailman DoS allows remote attackers to cause a denial of service by using
multipart MIME message with a single part MIME message.
Mailman cross site scripting bug allows remote attackers to inject arbitrary web
script in the form ofaction argument.
In Mailman Denial of Service application crash and server message "fail with an
Overflow on bad date data in a processed message".
http://www.redhat.com/archives/fedora-test-list/2006-May/msg00131.html
http://www.redhat.com/archives/fedora-package-announce/2006-May/msg00134.htm
http://www.redhat.com/archives/fedora-package-announce/2006-May/msg00135.
Bugzilla
CVE-2006-0052 Mailman DoS
bugzilla·2006-03-30·CVSS 5.0
CVE-2006-0052 [MEDIUM] CVE-2006-0052 Mailman DoS
CVE-2006-0052 Mailman DoS
Mailman DoS
It is possible to prevent a mailing list from functioning properly by
sending a misformed multipart message to a mailman list. This
malformed message would prevent new messages sent to a list from being
processed.
Fixed in 2.1.6
Here is the original message:
http://mail.python.org/pipermail/mailman-users/2005-June/045107.html
Here is the patch:
http://cvs.sourceforge.net/viewcvs.py/mailman/mailman/Mailman/Handlers/Scrubber.py?r1=2.18.2.12&r2=2.18.2.13
CVE-2006-0052 Doesn't affect: FC5 (version)
Discussion:
Please test:
http://www.redhat.com/archives/fedora-test-list/2006-May/msg00131.html
---
I am suspecting that this bug report is related to the mailman package that
was released in FEDORA-2006-534, mailman-2.1.8-0.FC4.1,
?
If so, should thi
Bugzilla
CVE-2006-0052 Mailman DoS
bugzilla·2006-03-30·CVSS 5.0
CVE-2006-0052 [MEDIUM] CVE-2006-0052 Mailman DoS
CVE-2006-0052 Mailman DoS
Mailman DoS
It is possible to prevent a mailing list from functioning properly by
sending a misformed multipart message to a mailman list. This
malformed message would prevent new messages sent to a list from being
processed.
Fixed in 2.1.6
Here is the original message:
http://mail.python.org/pipermail/mailman-users/2005-June/045107.html
Here is the patch:
http://cvs.sourceforge.net/viewcvs.py/mailman/mailman/Mailman/Handlers/Scrubber.py?r1=2.18.2.12&r2=2.18.2.13
CVE-2006-0052 Doesn't affect: FC5 (version)
This issue also affects RHEL3
Discussion:
No new package for RHEL after a month?
BTW: should a security related bug not get a dedicated mark?
---
Oops, there must be a problem in bugzilla. Like currently seen in
https://bugzilla.redhat.com/bugzilla/sh
ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.aschttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358892http://secunia.com/advisories/19522http://secunia.com/advisories/19545http://secunia.com/advisories/19571http://secunia.com/advisories/20624http://secunia.com/advisories/20782http://securitytracker.com/id?1015851http://www.debian.org/security/2006/dsa-1027http://www.mandriva.com/security/advisories?name=MDKSA-2006:061http://www.novell.com/linux/security/advisories/2006_08_sr.htmlhttp://www.osvdb.org/24367http://www.redhat.com/support/errata/RHSA-2006-0486.htmlhttp://www.securityfocus.com/bid/17311https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9475https://usn.ubuntu.com/267-1/ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.aschttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358892http://secunia.com/advisories/19522http://secunia.com/advisories/19545http://secunia.com/advisories/19571http://secunia.com/advisories/20624http://secunia.com/advisories/20782http://securitytracker.com/id?1015851http://www.debian.org/security/2006/dsa-1027http://www.mandriva.com/security/advisories?name=MDKSA-2006:061http://www.novell.com/linux/security/advisories/2006_08_sr.htmlhttp://www.osvdb.org/24367http://www.redhat.com/support/errata/RHSA-2006-0486.htmlhttp://www.securityfocus.com/bid/17311https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9475https://usn.ubuntu.com/267-1/
2006-03-31
Published