Bug 205652 - CVE-2006-4624 mailman logfile CRLF injection
Summary: CVE-2006-4624 mailman logfile CRLF injection
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: mailman
Version: 5
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Tomas Smetana
QA Contact:
URL:
Whiteboard: impact=low,source=vendorsec,reported=...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2006-09-07 20:41 UTC by Josh Bressers
Modified: 2007-11-30 22:11 UTC (History)
0 users

Fixed In Version: 2.1.9-0.fc5.1
Clone Of:
Environment:
Last Closed: 2007-05-03 13:13:46 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Josh Bressers 2006-09-07 20:41:17 UTC
mailman logfile CRLF injection

Text taken from MITRE:
CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1
allows remote attackers to spoof messages in the error log and
possibly trick the administrator into visiting malicious URLs via a
carriage return/line feed sequences in the URI.

The fix for this issue is here:
http://svn.sourceforge.net/viewvc/mailman/?revision=7918&view=rev

Comment 1 David Eisenstein 2006-10-07 15:02:29 UTC
Bug #206607 also lists these two additional CVE's:  CVE-2006-3636 CVE-2006-2941.
The solution for FC6Test3 was to upgrade to mailman 2.1.9.  Any plans to do
likewise for this bug as well?

Those issues bring the current FC5 mailman to a security impact of "moderate,"
I believe?

Comment 2 Tomas Smetana 2007-05-03 13:13:46 UTC
The version 2.1.9 is available in FC-5 updates.


Note You need to log in before you can comment on or make changes to this bug.