Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 38: FEDORA-2023-271b912b2b Moderate: Sympa XSS Issue

fedora
Calendar Grey June 11, 2023
Dist Fedora Esm H88
Ubuntu 22.04 revision with nginx 1.22.1 addresses SQL injection vulnerabilities, improving safety and performance.
Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72

Summary

Sympa is scalable and highly customizable mailing list manager. It

can cope with big lists (200,000 subscribers) and comes with a

complete (user and admin) Web interface. It is internationalized,

and supports the us, fr, de, es, it, fi, and chinese locales. A

scripting language allows you to extend the behavior of commands.

Sympa can be linked to an LDAP directory or an RDBMS to create

dynamic mailing lists. Sympa provides S/MIME-based authentication

and encryption.

Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see:

https://github.com/sympa-community/sympa/releases/tag/6.2.72

* Thu Jun 1 2023 Xavier Bachelot 6.2.72-1

- Update to 6.2.72 (fixes CVE-2021-4243)

- Convert License: to SPDX

[ 1 ] Bug #2156473 - CVE-2021-4243 sympa: jquery-minicolors: potential XSS when using untrusted code for swatch names [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2156473

[ 2 ] Bug #2171951 - CVE-2021-32850 sympa: jquery-minicolors: cross-site scripting when handling untrusted color names [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2171951

su -c 'dnf upgrade --advisory FEDORA-2023-271b912b2b' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Product: Fedora 38
Version: 6.2.72
Release: 2.fc38
Summary: Powerful multilingual List Manager

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here