Description
CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.
CVSS vector
AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9Complexity: High
Confidentiality: None
Availability: None
Affected Packages1 packages
🔴Vulnerability Details
2GHSAGHSA-pr3g-gx73-r4cm: CRLF injection vulnerability in Utils↗2022-05-01 ▶ CVEListCVE-2006-4624: CRLF injection vulnerability in Utils↗2006-09-07 ▶ 📋Vendor Advisories
1Red Hatmailman logfile CRLF injection↗2006-06-23 ▶ 💬Community
5BugzillaCVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)↗2006-10-20 ▶ BugzillaCVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)↗2006-10-07 ▶ BugzillaCVE-2006-4624 mailman 2.1.9 needed (CVE-2006-3636 CVE-2006-2941)↗2006-09-15 ▶ BugzillaCVE-2006-4624 mailman logfile CRLF injection↗2006-09-07 ▶ BugzillaCVE-2006-4624 mailman logfile CRLF injection↗2006-09-07 ▶