Linefeeds and carriage returns were not being stripped from email headers, raising the possibility of bogus headers being inserted into outgoing email.
Credit:
The information has been provided by Norrin, kbahey.
Vulnerable Systems:
* Drupal versions before 4.6.6.
Linefeeds and carriage returns were not being stripped from email headers, raising the possibility of bogus headers being inserted into outgoing email.
This could lead to Drupal sites being used to send unwanted email.
Vendor Status:
Drupal as issued an update for this vulnerablity.