CVE-2006-2191
published 2006-09-19CVE-2006-2191: Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.49%
82.7th percentile
Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this vulnerability, stating that it is "unexploitable.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | <= 2.1.8 | — |
| gnu | mailman | >= 0 < 1:2.1.9-1 | 1:2.1.9-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2gpc-wgcp-jq34: ** DISPUTED ** Format string vulnerability in Mailman before 2
ghsa_unreviewed·2022-05-01
CVE-2006-2191 [HIGH] GHSA-2gpc-wgcp-jq34: ** DISPUTED ** Format string vulnerability in Mailman before 2
** DISPUTED ** Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this vulnerability, stating that it is "unexploitable."
OSV
CVE-2006-2191: Format string vulnerability in Mailman before 2
osv·2006-09-19·CVSS 7.5
CVE-2006-2191 [HIGH] CVE-2006-2191: Format string vulnerability in Mailman before 2
Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this vulnerability, stating that it is "unexploitable.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://mail.python.org/pipermail/mailman-announce/2006-September/000087.htmlhttp://people.debian.org/~terpstra/message/20060906.155339.0c0732a4.en.htmlhttp://secunia.com/advisories/21732http://secunia.com/advisories/22639http://www.novell.com/linux/security/advisories/2006_25_sr.htmlhttp://mail.python.org/pipermail/mailman-announce/2006-September/000087.htmlhttp://people.debian.org/~terpstra/message/20060906.155339.0c0732a4.en.htmlhttp://secunia.com/advisories/21732http://secunia.com/advisories/22639http://www.novell.com/linux/security/advisories/2006_25_sr.html
2006-09-19
Published