SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-4624

CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.

LOW 2.6EPSS 2.93%

Does this matter?

Lower severity and a low EPSS score (2.93%). Track it; it rarely justifies an emergency change on its own.

Description

CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS
2.93% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
gnu/mailman
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.