Sympa Multiple Security Bypass Vulnerabilities
by Carol~
- 5/14/12 1:13 PM
In Reply to: VULNERABILITIES / FIXES - May 14, 2012 by Carol~
Release Date : 2012-05-14
Criticality level : Moderately critical
Impact : Security Bypass
Where : From remote
Solution Status : Vendor Patch
Software: Sympa 6.x
Description:
Multiple vulnerabilities have been reported in Sympa, which can be exploited by malicious people to bypass certain security restrictions.
The vulnerabilities are caused due to the application allowing access to archive functions without checking credentials. This can be exploited to create, download, and delete an archive.
The vulnerabilities are reported in versions prior to 6.1.11.
Solution:
Update to version 6.1.11.
Original Advisory:
http://www.sympa.org/distribution/latest-stable/NEWS
http://www.openwall.com/lists/oss-security/2012/05/11/8
http://secunia.com/advisories/49045/

Moderator
CNET Staff
Samsung Staff
Dell Staff