Sympa Multiple Security Bypass Vulnerabilities

by Carol~ Moderator - 5/14/12 1:13 PM

In Reply to: VULNERABILITIES / FIXES - May 14, 2012 by Carol~ Moderator

Release Date : 2012-05-14

Criticality level : Moderately critical
Impact : Security Bypass
Where : From remote
Solution Status : Vendor Patch

Software: Sympa 6.x

Description:
Multiple vulnerabilities have been reported in Sympa, which can be exploited by malicious people to bypass certain security restrictions.

The vulnerabilities are caused due to the application allowing access to archive functions without checking credentials. This can be exploited to create, download, and delete an archive.

The vulnerabilities are reported in versions prior to 6.1.11.

Solution:
Update to version 6.1.11.

Original Advisory:
http://www.sympa.org/distribution/latest-stable/NEWS
http://www.openwall.com/lists/oss-security/2012/05/11/8

http://secunia.com/advisories/49045/