DSA-4285-1 sympa -- security update

Related Vulnerabilities: CVE-2018-1000550  

Michael Kaczmarczik discovered a vulnerability in the web interface template editing function of Sympa, a mailing list manager. Owner and listmasters could use this flaw to create or modify arbitrary files in the server with privileges of sympa user or owner view list config files even if edit_list.conf prohibits it. For the stable distribution (stretch), this problem has been fixed in version 6.2.16~dfsg-3+deb9u1. We recommend that you upgrade your sympa packages. For the detailed security status of sympa please refer to its security tracker page at: https://security-tracker.debian.org/tracker/sympa

Debian Security Advisory

DSA-4285-1 sympa -- security update

Date Reported:
05 Sep 2018
Affected Packages:
sympa
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-1000550.
More information:

Michael Kaczmarczik discovered a vulnerability in the web interface template editing function of Sympa, a mailing list manager. Owner and listmasters could use this flaw to create or modify arbitrary files in the server with privileges of sympa user or owner view list config files even if edit_list.conf prohibits it.

For the stable distribution (stretch), this problem has been fixed in version 6.2.16~dfsg-3+deb9u1.

We recommend that you upgrade your sympa packages.

For the detailed security status of sympa please refer to its security tracker page at: https://security-tracker.debian.org/tracker/sympa