sympa-community.github.io

Incubating the new Sympa documentation site

2018-001 Security flaws in template editing

The Sympa Community
2018-07-03 (Update)

Synopsis

A fix is available for a vulnerability discovered in Sympa web interface.

Systems Affected

Problem Description

A vulnerability has been discovered in Sympa web interface that allows write access to files on the server filesystem.

This flaw allows to create or modify any file writable by the Sympa user, located on the server filesystem, using the function of Sympa web interface template file saving.

Impact

Possibility to create or modify files on the server filesystem.

Workarounds

Users who can’t upgrade to the latest version have the following workaround solution: Disable access to corresponding function through the web interface.

Solution

or

Versions prior to 6.2 are no longer maintained. Users of these versions should upgrade to 6.2.32 to prevent potential attacks.

CVE Numbers

CVE-2018-1000550

References

Acknowledgements

The security flaw this advisory describes was reported by Michael Kaczmarczik, UT Austin ITS, Systems Enterprise Services, working with the UT Austin Information Security Office.

This advisory was published with assistance by CERT RENATER.

Change log

CC BY-SA 4.0 Unless otherwise specified, the contents of this document are licensed under the Creative Commons - Attribution - ShareAlike license. For more details see LICENSE and AUTHORS.

Theme originally designed by orderedlist