Vulnerability Bulletins

DSA-4285 sympa - security update

   
Affected software Debian
 
Michael Kaczmarczik discovered a vulnerability in the web interfacetemplate editing function of Sympa, a mailing list manager. Owner andlistmasters could use this flaw to create or modify arbitrary files inthe server with privileges of sympa user or owner view list config fileseven if edit_list.conf prohibits it.

More info:

https://www.debian.org/security/2018/dsa-4285