Sicherheit: Mangelnde Eingabeprüfung in sympa
Aktuelle Meldungen Distributionen
Name: Mangelnde Eingabeprüfung in sympa
ID: FEDORA-2021-a5570c5281
Distribution: Fedora
Plattformen: Fedora 32
Datum: Mi, 13. Januar 2021, 07:08
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29668
Applikationen: Sympa


Fedora Update Notification
2021-01-13 01:35:03.822505

Name : sympa
Product : Fedora 32
Version : 6.2.60
Release : 1.fc32
URL : http://www.sympa.org
Summary : Powerful multilingual List Manager
Description :
Sympa is scalable and highly customizable mailing list manager. It
can cope with big lists (200,000 subscribers) and comes with a
complete (user and admin) Web interface. It is internationalized,
and supports the us, fr, de, es, it, fi, and chinese locales. A
scripting language allows you to extend the behavior of commands.
Sympa can be linked to an LDAP directory or an RDBMS to create
dynamic mailing lists. Sympa provides S/MIME-based authentication
and encryption.

Update Information:

Update to 6.2.60 Fixes CVE-2020-29668

* Mon Jan 4 2021 Xavier Bachelot <xavier@bachelot.org> 6.2.60-1
- Update to 6.2.60
- Fixes CVE-2020-29668 (RHBZ#1906576)
* Sat Nov 7 2020 Xavier Bachelot <xavier@bachelot.org> 6.2.58-2
- Add BR: perl-Test-Net-LDAP
- Remove all of EL6 thus sysvinit support

[ 1 ] Bug #1906577 - CVE-2020-29668 sympa: allows remote attackers to obtain
full SOAP API access via illegal cookie [fedora-all]
[ 2 ] Bug #1906578 - CVE-2020-29668 sympa: allows remote attackers to obtain
full SOAP API access via illegal cookie [epel-7]

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-a5570c5281' at the command
line. For more information, refer to the dnf documentation available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Pro-Linux @Facebook
Neue Nachrichten