MGASA-2015-0085

Source
https://advisories.mageia.org/MGASA-2015-0085.html
Import Source
https://advisories.mageia.org/MGASA-2015-0085.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0085
Upstream
  • CVE-2014-1306
Published
2015-02-26T08:26:53Z
Modified
2026-04-16T06:23:00.145748172Z
Summary
Updated sympa packages fix CVE-2015-1306
Details

Updated sympa packages fix security vulnerability:

A vulnerability have been discovered in Sympa web interface that allows access to files on the server filesystem. This breach allows to send to a list or a user any file readable by the Sympa user, located on the server filesystem, using the Sympa web interface newsletter posting area (CVE-2015-1306).

References
Credits

Affected packages

Mageia:4 / sympa

Package

Name
sympa
Purl
pkg:rpm/mageia/sympa?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.17-3.3.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0085.json"