MGASA-2015-0085
Dashboard / Vulnerabilities / MGASA-2015-0085
Summary: Updated sympa packages fix CVE-2015-1306
Details: Updated sympa packages fix security vulnerability: A vulnerability have been discovered in Sympa web interface that allows access to files on the server filesystem. This breach allows to send to a list or a user any file readable by the Sympa user, located on the server filesystem, using the Sympa web interface newsletter posting area (CVE-2015-1306).
References: https://advisories.mageia.org/MGASA-2015-0085.html, https://bugs.mageia.org/show_bug.cgi?id=15097, https://www.sympa.org/security_advisories#security_breaches_in_newsletter_posting, https://www.debian.org/security/2015/dsa-3134
Affected packages
Package
Name: sympa
Purl: pkg:rpm/mageia/sympa?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
