sympa: CVE-2020-9369: Security flaws in CSRF prevention

Related Vulnerabilities: CVE-2020-9369  

Debian Bug report logs - #952428
sympa: CVE-2020-9369: Security flaws in CSRF prevention

version graph

Package: sympa; Maintainer for sympa is Debian Sympa team <sympa@packages.debian.org>; Source for sympa is src:sympa (PTS, buildd, popcon).

Reported by: "Stefan Hornburg (Racke)" <racke@linuxia.de>

Date: Mon, 24 Feb 2020 10:21:02 UTC

Severity: critical

Tags: patch, security, upstream

Found in versions sympa/6.2.40~dfsg-1, sympa/6.2.40~dfsg-3

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian Sympa team <sympa@packages.debian.org>:
Bug#952428; Package sympa. (Mon, 24 Feb 2020 10:21:04 GMT) (full text, mbox, link).


Acknowledgement sent to "Stefan Hornburg (Racke)" <racke@linuxia.de>:
New Bug report received and forwarded. Copy sent to Debian Sympa team <sympa@packages.debian.org>. (Mon, 24 Feb 2020 10:21:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: "Stefan Hornburg (Racke)" <racke@linuxia.de>
To: submit@bugs.debian.org
Subject: Security flaws in CSRF prevention
Date: Mon, 24 Feb 2020 10:43:39 +0100
[Message part 1 (text/plain, inline)]
package: sympa
severity: critical
version: 6.2.40~dfsg-3
tags: patch

A vulnerability has been discovered in Sympa web interface that can
cause denial of service (DoS) attack.

By submitting requests with malformed parameters, this flaw allows to
create junk files in Sympa's directory for temporary files.  And
particularly by tampering token to prevent CSRF, it allows to originate
excessive notification messages to listmasters.

Full advisory:

https://sympa-community.github.io/security/2020-001.html

Regards
           Racke

-- 
Ecommerce and Linux consulting + Perl and web application programming.
Debian and Sympa administration. Provisioning with Ansible.
[sympa-6.2.52-sa-2020-001.patch (text/x-patch, attachment)]
[signature.asc (application/pgp-signature, attachment)]

Marked as found in versions sympa/6.2.40~dfsg-1. Request was from "Stefan Hornburg (Racke)" <racke@linuxia.de> to control@bugs.debian.org. (Mon, 24 Feb 2020 11:51:02 GMT) (full text, mbox, link).


Added tag(s) upstream and security. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Mon, 24 Feb 2020 21:09:03 GMT) (full text, mbox, link).


Changed Bug title to 'sympa: CVE-2020-9369: Security flaws in CSRF prevention' from 'Security flaws in CSRF prevention'. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Mon, 24 Feb 2020 21:09:04 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Tue Feb 25 09:27:47 2020; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.