MGASA-2019-0263

Source
https://advisories.mageia.org/MGASA-2019-0263.html
Import Source
https://advisories.mageia.org/MGASA-2019-0263.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0263
Upstream
Published
2019-09-12T19:09:52Z
Modified
2026-06-04T05:30:04Z
Summary
Updated sympa packages fix security vulnerability
Details

Updated sympa packages fix security vulnerability:

Michael Kaczmarczik discovered a vulnerability in the web interface template editing function of Sympa, a mailing list manager. Owner and listmasters could use this flaw to create or modify arbitrary files in the server with privileges of sympa user or owner view list config files even if edit_list.conf prohibits it (CVE-2018-1000550).

References
Credits

Affected packages

Mageia:6 / sympa

Package

Name
sympa
Purl
pkg:rpm/mageia/sympa?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.2.16-1.1.mga6

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2019-0263.json"