Lucene search

K
freebsdFreeBSD9908A1CC-35AD-424D-BE0B-7E56ABD5931A
HistoryFeb 24, 2020 - 12:00 a.m.

sympa -- Denial of service caused by malformed CSRF token

2020-02-2400:00:00
vuxml.freebsd.org
13

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.026

Percentile

90.4%

Javier Moreno discovered a vulnerability in Sympa web
interface that can cause denial of service (DoS) attack.
By submitting requests with malformed parameters, this
flaw allows to create junk files in Sympa’s directory
for temporary files. And particularly by tampering token
to prevent CSRF, it allows to originate exessive
notification messages to listmasters.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchsympa< 6.2.54UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.026

Percentile

90.4%