USN-4442-1
Dashboard / Vulnerabilities / USN-4442-1
USN-4442-1
Summary: sympa vulnerabilities
Details: Michael Kaczmarczik discovered that Sympa incorrectly handled HTTP GET/POST requests. An attacker could possibly use this issue to insert, edit or obtain sensitive information. (CVE-2018-1000550) It was discovered that Sympa incorrectly handled URL parameters. An attacker could possibly use this issue to perform XSS attacks. (CVE-2018-1000671) Nicolas Chatelain discovered that Sympa incorrectly handled environment variables. An attacker could possibly use this issue with a setuid binary and gain root privileges. (CVE-2020-10936)
References: https://ubuntu.com/security/notices/USN-4442-1, https://ubuntu.com/security/CVE-2018-1000550, https://ubuntu.com/security/CVE-2018-1000671, https://ubuntu.com/security/CVE-2020-10936
Affected packages
Package
Name: sympa
Purl: pkg:deb/ubuntu/[email protected]~dfsg-1ubuntu0.1~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
