LWN.net Logo

sympa: authorization bypass

Package(s):sympa CVE #(s):CVE-2012-2352
Created:May 21, 2012 Updated:July 12, 2012
Description: From the Debian advisory:

Several vulnerabilities have been discovered in Sympa, a mailing list manager, that allow to skip the scenario-based authorization mechanisms. This vulnerability allows to display the archives management page, and download and delete the list archives by unauthorized users.

Alerts:
Debian DSA-2477-1 2012-05-20
Mageia MGASA-2012-0160 2012-07-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds