Subject: Announcements of new sympa release
List archive
[sympa-announce] 2012-001 Security breaches in archives management
- From: David Verdin <>
- To:
- Subject: [sympa-announce] 2012-001 Security breaches in archives management
- Date: Tue, 15 May 2012 16:37:56 +0200
______________________________________________________________ ______________ English version _________________________________ 2012-001 Security breaches in archives management1. ThreatPossibility to bypass the authorization mechanisms in the archive management page.2. Systems AffectedAll Sympa branches are affected.
3. SummaryMultiple vulnerabilities have been discovered in Sympa archive management that allow to skip the scenario-based authorization mechanisms.This breach allows to:
4. Solution
Older versions are no longer maintained. Users of this version should upgrade to 6.1.11 or 6.0.7 to prevent potential attacks. 5 - LinksSympa 6.0.7 and 6.1.11 releasedhttps://listes.renater.fr/sympa/arc/sympa-announce/2012-05/msg00001.html Sympa 6.1.11 released https://www.sympa.org/#sympa_6111_released Avis de sécurité Sympa 2012-001 https://www.sympa.org/security_advisories#security_breaches_in_archives_management ______________________________________________________________ ______________ French version _________________________________ 2012-001 Failles de sécurité dans la gestion des archives de listes1. RisqueContournement des droits de gestion des archives2. Systèmes affectésToutes les branches de Sympa sont concernées.
3. RésuméDes vulnérabilités multiples ont été découvertes dans Sympa, permettant de contourner les scénarios d'autorisation de Sympa.La faille permet :
4. Solution
Les versions antérieures ne sont plus maintenues. Les utilisateurs de ces versions sont invités à passer aux versions 6.1.11 ou 6.0.7 pour se protéger d'attaques éventuelles. 5 - LiensSympa 6.0.7 and 6.1.11 releasedhttps://listes.renater.fr/sympa/arc/sympa-announce/2012-05/msg00001.html Sympa 6.1.11 released https://www.sympa.org/#sympa_6111_released Sympa security advisory 2012-001 https://www.sympa.org/security_advisories#security_breaches_in_archives_management |
Attachment:
smime.p7s
Description: Signature cryptographique S/MIME
- [sympa-announce] 2012-001 Security breaches in archives management, David Verdin, 05/15/2012
Archive powered by MHonArc 2.6.19+.