MGASA-2019-0263
Dashboard / Vulnerabilities / MGASA-2019-0263
Summary: Updated sympa packages fix security vulnerability
Details: Updated sympa packages fix security vulnerability: Michael Kaczmarczik discovered a vulnerability in the web interface template editing function of Sympa, a mailing list manager. Owner and listmasters could use this flaw to create or modify arbitrary files in the server with privileges of sympa user or owner view list config files even if edit_list.conf prohibits it (CVE-2018-1000550).
References: https://advisories.mageia.org/MGASA-2019-0263.html, https://bugs.mageia.org/show_bug.cgi?id=23536, https://sympa-community.github.io/security/2018-001.html, https://www.debian.org/security/2018/dsa-4285
Affected packages
Package
Name: sympa
Purl: pkg:rpm/mageia/sympa?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
