CVE-2005-3573: Medium severity GNU Mailman vulnerability
Published Nov 16, 2005
·Updated
Scrubber.py in Mailman 2.1.5-8 does not properly handle UTF8 character encodings in filenames of e-mail attachments, which allows remote attackers to cause a denial of service (application crash).
Affected Software
24 affected components
GNU Mailman=2.0-beta3
GNU Mailman=2.0-beta4
GNU Mailman=2.0-beta5
GNU Mailman=2.0.1
GNU Mailman=2.0.2
GNU Mailman=2.0.3
GNU Mailman=2.0.4
GNU Mailman=2.0.5
GNU Mailman=2.0.6
GNU Mailman=2.0.7
GNU Mailman=2.0.8
GNU Mailman=2.0.9
GNU Mailman=2.0.10
GNU Mailman=2.0.11
GNU Mailman=2.0.12
GNU Mailman=2.0.13
GNU Mailman=2.0.14
GNU Mailman=2.1
GNU Mailman=2.1.1-beta1
GNU Mailman=2.1.2
GNU Mailman=2.1.3
GNU Mailman=2.1.4
GNU Mailman=2.1.5
GNU Mailman=2.1.5.8
Event History
Nov 16, 2005
CVE Published
07:42 AM
CVE Published
via MITRE·12:37 PM
Data Sourced
via MITRE·12:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3573?
CVE-2005-3573 is classified as a denial of service vulnerability.
2
How do I fix CVE-2005-3573?
To fix CVE-2005-3573, upgrade Mailman to version 2.1.6 or later.
3
What software is affected by CVE-2005-3573?
CVE-2005-3573 affects various versions of Mailman, including 2.1.5 and earlier versions.
4
Can CVE-2005-3573 lead to data loss?
CVE-2005-3573 primarily results in application crashes, which may lead to temporary disruptions but not direct data loss.
5
Is there a workaround for CVE-2005-3573?
A workaround for CVE-2005-3573 is to avoid allowing attachments with problematic UTF-8 filenames until a patch is applied.