First published: Tue Sep 19 2006(Updated: )
** DISPUTED ** Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this vulnerability, stating that it is "unexploitable."
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Mailman | <=2.1.8 | |
Mailman | <=2.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-2191 is disputed, with the vendor stating it is unexploitable.
To fix CVE-2006-2191, upgrade Mailman to version 2.1.9 or later.
Mailman versions prior to 2.1.9, specifically up to 2.1.8, are affected by CVE-2006-2191.
CVE-2006-2191 is a format string vulnerability that may allow arbitrary code execution.
The vendor has disputed the existence of an exploitable vulnerability in CVE-2006-2191.