Skip to Content.
Sympa Menu

en - Re: [en@sympa] SQL injection

Subject: The mailing list for listmasters using Sympa

List archive

Chronological Thread  
  • From: Matthew Goebel <address@concealed>
  • To: Harald Weidner <address@concealed>
  • Cc: address@concealed
  • Subject: Re: [en@sympa] SQL injection
  • Date: Mon, 20 Jan 2025 10:21:39 -0500

Is this in regards to the comments in :: https://github.com/sympa-community/sympa/issues/1654 ?

Thanks,
Matt

On Sat, Jan 18, 2025 at 7:07 AM Harald Weidner <address@concealed> wrote:
Hello,

> > It seems there's an SQL injection bug for Sympa 6.2.70 (from Debian).  I
> > can't find any docs on this.  Is this known?

> Please provide sensitive information about security flaw to
> <address@concealed <mailto:address@concealed>>.  Thank you.

Is there any news on this topic? Does the SQL injection vulnerability exist,
and is version 6.2.70 in Debian stable affected?

Best regards,
Harald


--
Matthew Goebel : maddress@concealed : Unix Jockey @ EMU : Hail Eris
Neo-Student, Net Lurker, Donut consumer, and procrastinating medher...
 "Always with the negative waves, Moriarty" - Oddball
 "Comfort the troubled, and trouble the comfortable." - Dietrich Bonhoeffer





Archive powered by MHonArc 2.6.19+.

Top of Page