Micah Anderson
2012-May-14 14:45 UTC
[Secure-testing-team] Bug#672893: security: private archives available to all
Package: sympa Version: 6.0.1+dfsg-4 Severity: grave Tags: security patch Justification: user security hole It is possible to open the archive management ("arc_manage") page for any list, even those set to only be available to members, giving anyone the option to download the archive, or delete the archive. http://www.sympa.org/distribution/latest-stable/NEWS Patch for the version in stable: https://sourcesup.renater.fr/scm/viewvc.php/branches/sympa-6.0-branch/wwsympa/wwsympa.fcgi.in?root=sympa&r1=6706&r2=7358&pathrev=7358 Please reference CVE-2012-2352 in any changelogs addressing this issue. micah System Information: Debian Release: wheezy/sid Architecture: amd64 (x86_64) Kernel: Linux 3.2.0-1-amd64 (SMP w/2 CPU cores) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash