The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.mandriva.com/security/advisories?name=MDVSA-2015:051 | vendor advisory |
http://www.openwall.com/lists/oss-security/2015/01/20/4 | mailing list |
https://www.sympa.org/security_advisories | patch vendor advisory |
http://secunia.com/advisories/62387 | third party advisory |
http://www.securityfocus.com/bid/72277 | vdb entry |
http://secunia.com/advisories/62442 | third party advisory |
http://advisories.mageia.org/MGASA-2015-0085.html | |
http://www.debian.org/security/2015/dsa-3134 | vendor advisory |