5
CVSSv2

CVE-2003-0991

Published: 03/03/2004 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Unknown vulnerability in the mail command handler in Mailman prior to 2.0.14 allows remote malicious users to cause a denial of service (crash) via malformed e-mail commands.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu mailman 1.0

gnu mailman 2.0.13

gnu mailman 2.0.2

gnu mailman 2.0.3

gnu mailman 2.0

gnu mailman 1.1

gnu mailman 2.0.4

gnu mailman 2.0.5

gnu mailman 2.0.11

gnu mailman 2.0.12

gnu mailman 2.0.8

gnu mailman 2.0.9

gnu mailman 2.1

gnu mailman 2.0.1

gnu mailman 2.0.10

gnu mailman 2.0.6

gnu mailman 2.0.7

sgi propack 2.3

Vendor Advisories

Several vulnerabilities have been fixed in the mailman package: CAN-2003-0038 - potential cross-site scripting via certain CGI parameters (not known to be exploitable in this version) CAN-2003-0965 - cross-site scripting in the administrative interface CAN-2003-0991 - certain malformed email commands could cause the mailman process to crash ...