CVE-2006-4624
CVE-2006-4624 is a low-severity vulnerability in Gnu Mailman with a CVSS 2.0 base score of 2.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: Low (CVSS 2.0 base score 2.6)
- EPSS exploit prediction: 3% (86th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Gnu Mailman
- Published:
- Last modified:
Description
CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.
Frequently asked questions
- What is CVE-2006-4624?
- CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.
- How severe is CVE-2006-4624?
- CVE-2006-4624 has a CVSS 2.0 base score of 2.6, rated low severity.
- Is CVE-2006-4624 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (86th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2006-4624?
- CVE-2006-4624 affects Gnu Mailman. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2006-4624?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2006-4624 published?
- CVE-2006-4624 was published on 2006-09-07 and last updated on 2026-06-16.
References
- http://mail.python.org/pipermail/mailman-announce/2006-September/000087.html
- http://moritz-naumann.com/adv/0013/mailmanmulti/0013.txt
- http://secunia.com/advisories/21732
- http://secunia.com/advisories/22011
- http://secunia.com/advisories/22020
- http://secunia.com/advisories/22227
- http://secunia.com/advisories/22639
- http://secunia.com/advisories/27669
- http://security.gentoo.org/glsa/glsa-200609-12.xml
- http://sourceforge.net/project/shownotes.php?group_id=103&release_id=444295
- http://svn.sourceforge.net/viewvc/mailman/trunk/mailman/Mailman/Utils.py?r1=7859&r2=7923
- http://www.debian.org/security/2006/dsa-1188
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:165
- http://www.novell.com/linux/security/advisories/2006_25_sr.html
- http://www.redhat.com/support/errata/RHSA-2007-0779.html
- http://www.securityfocus.com/archive/1/445992/100/0/threaded
- http://www.securityfocus.com/bid/19831
- http://www.securityfocus.com/bid/20021
- http://www.vupen.com/english/advisories/2006/3446
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28734
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9756
Affected products (1)
- cpe:2.3:a:gnu:mailman:*:*:*:*:*:*:*:*
More vulnerabilities in Gnu Mailman
- CVE-2021-44227 — High (CVSS 8.8): In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that…
- CVE-2016-7123 — High (CVSS 8.8): Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote…
- CVE-2016-6893 — High (CVSS 8.8): Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows…
- CVE-2021-42097 — High (CVSS 8.0): GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user…
- CVE-2005-4153 — High (CVSS 7.8): Mailman 2.1.4 through 2.1.6 allows remote attackers to cause a denial of service via a message that causes the server…
- CVE-2015-2775 — High (CVSS 7.6): Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers…
All CVEs affecting Gnu Mailman →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-76605 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-76604 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The…
- CVE-2026-67364 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1:…
- CVE-2026-73343 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- CVE-2026-74253 — Critical (CVSS 10.0): Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0…
- CVE-2026-73678 — Critical (CVSS 10.0): MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that…