5
CVSSv2

CVE-2020-9369

Published: 24/02/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Sympa 6.2.38 up to and including 6.2.52 allows remote malicious users to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sympa sympa

fedoraproject fedora 30

fedoraproject fedora 31

fedoraproject fedora 32

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #952428 sympa: CVE-2020-9369: Security flaws in CSRF prevention Package: sympa; Maintainer for sympa is Debian Sympa team <sympa@packagesdebianorg>; Source for sympa is src:sympa (PTS, buildd, popcon) Reported by: "Stefan Hornburg (Racke)" <racke@linuxiade> Date: Mon, 24 Feb 2020 10:21:02 ...
Several vulnerabilities were discovered in Sympa, a mailing list manager, which could result in local privilege escalation, denial of service or unauthorized access via the SOAP API Additionally to mitigate CVE-2020-26880 the sympa_newaliases-wrapper is no longer installed setuid root by default A new Debconf question is introduced to allow setui ...