Debian Security Update DSA-4285 sympa - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,817
Reaction score
74
Credits
-1,257
Michael Kaczmarczik discovered a vulnerability in the web interface template editing function of Sympa, a mailing list manager. Owner and listmasters could use this flaw to create or modify arbitrary files in the server with privileges of sympa user or owner view list config files even if edit_list.conf prohibits it.

Continue reading...
 


Follow Linux.org

Members online


Top