CVE-2006-1225

Publication date 14 March 2006

Last updated 17 July 2025


Ubuntu priority

Description

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.

Status

Package Ubuntu Release Status
drupal 8.04 LTS hardy Not in release
7.10 gutsy Not in release
7.04 feisty Ignored end of life, was needed
6.10 edgy
Fixed 4.5.8-1
6.06 LTS dapper
Fixed 4.5.8-1


Access our resources on patching vulnerabilities