CVE-2006-2941
published 2006-09-06CVE-2006-2941: Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.45%
82.7th percentile
Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
mailman vulnerabilities
vendor_ubuntu·2006-09-13·CVSS 5.0
CVE-2006-3636 [MEDIUM] mailman vulnerabilities
Title: mailman vulnerabilities
Summary: mailman vulnerabilities
Steve Alexander discovered that mailman did not properly handle
attachments with special filenames. A remote user could exploit that
to stop mail delivery until the server administrator manually cleaned
these posts. (CVE-2006-2941)
Various cross-site scripting vulnerabilities have been reported by
Barry Warsaw. By using specially crafted email addresses, names, and
similar arbitrary user-defined strings, a remote attacker could
exploit this to run web script code in the list administrator's
web browser. (CVE-2006-3636)
URLs logged to the error log file are now checked for invalid
characters. Before, specially crafted URLs could inject arbitrary
messages into the log.
Instructions: In general, a standard system upgrade is
Red Hat
security flaw
vendor_redhat·2006-09-04·CVSS 5.0
CVE-2006-2941 [MEDIUM] security flaw
security flaw
Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".
GHSA
GHSA-8mm9-hcg3-394g: Mailman before 2
ghsa_unreviewed·2022-05-01
CVE-2006-2941 [MEDIUM] GHSA-8mm9-hcg3-394g: Mailman before 2
Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-2941 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2006-2941 [MEDIUM] CVE-2006-2941 security flaw
CVE-2006-2941 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".
Bugzilla
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
bugzilla·2006-10-20·CVSS 5.0
CVE-2006-4624 [MEDIUM] CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
+++ This bug was initially created as a clone of Bug #209891 +++
Cloning for FC3.
+++ This bug was initially created as a clone of Bug #206607 +++
FC6 needs mailman 2.1.9 to correct CVE-2006-4624, CVE-2006-3636, CVE-2006-2941
This bug is for FC3 and FC4. Upgrading to mailman 2.1.9 will correct these
vulnerabilities.
Discussion:
Oh okay. I guess I thought it was simpler to track a single issue in
just one bug report, but I guess splitting them out may help ... ? I
hope it does.
---
The current version of the .src.rpm is
mailman-2.1.5-32.fc3.src.rpm
at
---
Can someone check the src.rpm I made with the lateest mailman from legacy and
the patches from RHEL?
http://bugs.unl.edu.ar/~martin/mailman-2.1.5-33.fc3.legacy
Bugzilla
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
bugzilla·2006-10-07·CVSS 5.0
CVE-2006-4624 [MEDIUM] CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
+++ This bug was initially created as a clone of Bug #206607 +++
FC6 needs mailman 2.1.9 to correct CVE-2006-4624, CVE-2006-3636, CVE-2006-2941
This bug is for FC3 and FC4. Upgrading to mailman 2.1.9 will correct these
vulnerabilities.
Discussion:
In a fedora-legacy-list message (),
Martin Marques submitted mailman-2.1.8-1.FC4.1.legacy.src.rpm:
http://bugs.unl.edu.ar/~martin/mailman-2.1.8-1.FC4.1.legacy.src.rpm
This will need to be reviewed and packages built for updates-testing.
Work also needs to be done in the FC3 version of this bug, Bug #211676.
---
Fedora Core 4 is now completely unmaintained. These bugs can't be fixed in that
version. If the issue still persists in current Fedora Core, please reopen.
Thank yo
Bugzilla
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
bugzilla·2006-09-15·CVSS 5.0
CVE-2006-4624 [MEDIUM] CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
CVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)
FC6 needs mailman 2.1.9 to correct CVE-2006-4624, CVE-2006-3636, CVE-2006-2941
Bugzilla
CVE-2006-4624 mailman logfile CRLF injection
bugzilla·2006-09-07·CVSS 5.0
CVE-2006-4624 [MEDIUM] CVE-2006-4624 mailman logfile CRLF injection
CVE-2006-4624 mailman logfile CRLF injection
mailman logfile CRLF injection
Text taken from MITRE:
CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1
allows remote attackers to spoof messages in the error log and
possibly trick the administrator into visiting malicious URLs via a
carriage return/line feed sequences in the URI.
The fix for this issue is here:
http://svn.sourceforge.net/viewvc/mailman/?revision=7918&view=rev
Discussion:
Bug #206607 also lists these two additional CVE's: CVE-2006-3636 CVE-2006-2941.
The solution for FC6Test3 was to upgrade to mailman 2.1.9. Any plans to do
likewise for this bug as well?
Those issues bring the current FC5 mailman to a security impact of "moderate,"
I believe?
---
The version 2.1.9 is available in FC-5 updates.
Bugzilla
CVE-2006-2941 Mailman DoS
bugzilla·2006-07-11·CVSS 5.0
CVE-2006-2941 [MEDIUM] CVE-2006-2941 Mailman DoS
CVE-2006-2941 Mailman DoS
Ubuntu reported a possible Mailman DoS where a malformed message can cause the
mailman server to stop sending out email. Currently embargoed with no proposed
date.
Also may affect RHEL3, RHEL2.1
Discussion:
Created attachment 132224
Proposed patch from Ubuntu
---
embargo 20060718 1400 UTC
---
Embargo may be extended by request of Barry Warsaw. Please don't open this bug
at this time.
---
Ok, wrote some test cases. RHEL3 and RHEL4 are _NOT_ vulnerable, cause
python-2.3.4-14 has a email/Message.py which does not backtrace with strange
filenames.
---
RHEL3's python-2.2.3-5 also does not backtrace..
---
mailman from RHEL2.1 does not save attachements and does not parse any mime
message headers.
---
RHSA-2006:0600 is free for other things... sorry about
http://mail.python.org/pipermail/mailman-announce/2006-September/000087.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0600.htmlhttp://secunia.com/advisories/21732http://secunia.com/advisories/21792http://secunia.com/advisories/21837http://secunia.com/advisories/21879http://secunia.com/advisories/22011http://secunia.com/advisories/22020http://secunia.com/advisories/22639http://security.gentoo.org/glsa/glsa-200609-12.xmlhttp://securitytracker.com/id?1016808http://sourceforge.net/project/shownotes.php?group_id=103&release_id=444295http://svn.sourceforge.net/viewvc/mailman/trunk/mailman/Mailman/Utils.py?r1=7859&r2=7923http://www.mandriva.com/security/advisories?name=MDKSA-2006:165http://www.novell.com/linux/security/advisories/2006_25_sr.htmlhttp://www.securityfocus.com/bid/19831http://www.ubuntu.com/usn/usn-345-1http://www.vupen.com/english/advisories/2006/3446https://exchange.xforce.ibmcloud.com/vulnerabilities/28732https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9912http://mail.python.org/pipermail/mailman-announce/2006-September/000087.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0600.htmlhttp://secunia.com/advisories/21732http://secunia.com/advisories/21792http://secunia.com/advisories/21837http://secunia.com/advisories/21879http://secunia.com/advisories/22011http://secunia.com/advisories/22020http://secunia.com/advisories/22639http://security.gentoo.org/glsa/glsa-200609-12.xmlhttp://securitytracker.com/id?1016808http://sourceforge.net/project/shownotes.php?group_id=103&release_id=444295http://svn.sourceforge.net/viewvc/mailman/trunk/mailman/Mailman/Utils.py?r1=7859&r2=7923http://www.mandriva.com/security/advisories?name=MDKSA-2006:165http://www.novell.com/linux/security/advisories/2006_25_sr.htmlhttp://www.securityfocus.com/bid/19831http://www.ubuntu.com/usn/usn-345-1http://www.vupen.com/english/advisories/2006/3446https://exchange.xforce.ibmcloud.com/vulnerabilities/28732https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9912
2006-09-06
Published