Lucene search

K
mageiaGentoo FoundationMGASA-2015-0085
HistoryFeb 26, 2015 - 11:26 a.m.

Updated sympa packages fix CVE-2015-1306

2015-02-2611:26:53
Gentoo Foundation
advisories.mageia.org
13

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.005

Percentile

77.7%

Updated sympa packages fix security vulnerability: A vulnerability have been discovered in Sympa web interface that allows access to files on the server filesystem. This breach allows to send to a list or a user any file readable by the Sympa user, located on the server filesystem, using the Sympa web interface newsletter posting area (CVE-2015-1306).

OSVersionArchitecturePackageVersionFilename
Mageia4noarchsympa< 6.1.17-3.3sympa-6.1.17-3.3.mga4

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.005

Percentile

77.7%