CVE-2005-3573 Information

Description

Scrubber.py in Mailman 2.1.5-8 does not properly handle UTF8 character encodings in filenames of e-mail attachments which allows remote attackers to cause a denial of service (application crash).

Reference

ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=327732 http://lists.suse.com/archive/suse-security-announce/2006-Jan/0003.html http://mail.python.org/pipermail/mailman-users/2005-September/046523.html http://secunia.com/advisories/17511 http://secunia.com/advisories/17874 http://secunia.com/advisories/18456 http://secunia.com/advisories/18503 http://secunia.com/advisories/18612 http://secunia.com/advisories/19167 http://secunia.com/advisories/19196 http://secunia.com/advisories/19532 http://securitytracker.com/id?1015735 http://www.debian.org/security/2006/dsa-955 http://www.osvdb.org/20819 http://www.redhat.com/support/errata/RHSA-2006-0204.html http://www.securityfocus.com/bid/15408 http://www.trustix.org/errata/2006/0012/ http://www.ubuntu.com/usn/usn-242-1 http://www.vupen.com/english/advisories/2005/2404 http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:222 https://exchange.xforce.ibmcloud.com/vulnerabilities/23139 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A10038

Share on: