Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 31: FEDORA-2020-9b6c969aac Moderate: Sympa Remote Code Execution

fedora
Calendar Grey June 1, 2020
Dist Fedora Esm H88
Security Update for Fedora 31: sympa addresses identified vulnerabilities and enhances performance in the new release 6.2.56.
Update to sympa 6.2.56

Summary

Sympa is scalable and highly customizable mailing list manager. It

can cope with big lists (200,000 subscribers) and comes with a

complete (user and admin) Web interface. It is internationalized,

and supports the us, fr, de, es, it, fi, and chinese locales. A

scripting language allows you to extend the behavior of commands.

Sympa can be linked to an LDAP directory or an RDBMS to create

dynamic mailing lists. Sympa provides S/MIME-based authentication

and encryption.

Update to sympa 6.2.56. Fixes CVE-2020-10936. For details, see: -https://github.com/sympa-community/sympa/releases/tag/6.2.56 - https://www.sympa.community/security/2020-002.html

* Sun May 24 2020 Xavier Bachelot 6.2.56-1

- Update to 6.2.56 (Fixes CVE-2020-10936)

- Fix typo in url and also socket location in lighttpd configuration (RHBZ#1812325)

[ 1 ] Bug #1770783 - multicomponent wwsympa_url with mod_proxy_fcgi is broken

https://bugzilla.redhat.com/show_bug.cgi?id=1770783

[ 2 ] Bug #1812325 - Migration with lighttpd is broken

https://bugzilla.redhat.com/show_bug.cgi?id=1812325

su -c 'dnf upgrade --advisory FEDORA-2020-9b6c969aac' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 31
Version: 6.2.56
Release: 1.fc31
Summary: Powerful multilingual List Manager

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here