---
title: "CVE-2006-4624\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-4624?format=md
keywords: index, follow
---

# CVE-2006-4624

Publication date 7 September 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows
remote attackers to spoof messages in the error log and possibly trick the
administrator into visiting malicious URLs via CRLF sequences in the URI.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| mailman | 7.04 feisty | Fixed 2.1.8-2ubuntu2 |
| 6.10 edgy | Fixed 2.1.8-2ubuntu2 |
| 6.06 LTS dapper | Fixed 2.1.5-9ubuntu4.1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4624)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-4624)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-4624)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-4624)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-4624>
