Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Sympa could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-8552-1 July 15, 2026 sympa vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Sympa could allow unintended access to network services. Software Description: - sympa: mailing list management software Details: It was discovered that Sympa did not properly validate input on the generic SSO login. A remote attacker could possibly use this issue to perform a path traversal attack and gain unintended access. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS sympa 6.2.70~dfsg-2+deb12u1build0.24.04.1 Ubuntu 22.04 LTS sympa 6.2.66~dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS sympa 6.2.40~dfsg-4ubuntu0.20.04.1~esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS sympa 6.2.24~dfsg-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS sympa 6.1.24~dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro After a standard system update you need to restart sympa to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8552-1 CVE-2024-55919 Package Information: https://launchpad.net/ubuntu/+source/sympa/6.2.70~dfsg-2+deb12u1build0.24.04.1 . Unattended access to network services via Sympa on Ubuntu can be corrected by updating your system to the latest package versions.. Ubuntu security advisory, Sympa patch, network services access, remote accessvulnerability. . Severity: Important. LinuxSecurity.com Team
A flaw was found in Sympa’s web interface, a modern mailing list manager. An attacker may bypass authentication by using an arbitrary e-mail address when the generic SSO loging feature was enabled. For Debian 12 bookworm, this problem has been fixed in version 6.2.70~dfsg-2+deb12u1.. Debian LTS Advisory DLA-4668-1
Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-88ad2bee84 2024-12-26 01:20:11.418870+00:00 -------------------------------------------------------------------------------- Name : sympa Product : Fedora 41 Version : 6.2.74 Release : 1.fc41 URL : http://www.sympa.org Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. -------------------------------------------------------------------------------- Update Information: Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 16 2024 Xavier Bachelot - 6.2.74-1 - Update to 6.2.74, fix for CVE-2024-55919 - Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-88ad2bee84' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-14c006b8bb 2024-12-25 01:38:03.924476+00:00 -------------------------------------------------------------------------------- Name : sympa Product : Fedora 40 Version : 6.2.74 Release : 1.fc40 URL : http://www.sympa.org Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. -------------------------------------------------------------------------------- Update Information: Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 16 2024 Xavier Bachelot - 6.2.74-1 - Update to 6.2.74, fix for CVE-2024-55919 - Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-14c006b8bb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Sympa 6.2.72 fixes many bugs, including the security one related in CVE-2021-32850 It is required to manually run sympa upgrade after get this update References: . MGASA-2024-0052 - Updated sympa packages fix security vulnerabilities Publication date: 29 Feb 2024 URL: https://advisories.mageia.org/MGASA-2024-0052.html Type: security Affected Mageia releases: 9 CVE: CVE-2021-32850 Sympa 6.2.72 fixes many bugs, including the security one related in CVE-2021-32850 It is required to manually run sympa upgrade after get this update References: - https://bugs.mageia.org/show_bug.cgi?id=32896 - https://github.com/sympa-community/sympa/releases/tag/6.2.72 - https://www.cve.org/CVERecord?id=CVE-2021-32850 - https://www.cve.org/CVERecord?id=CVE-2021-32850 SRPMS: - 9/core/sympa-6.2.72-4.mga9 . Mageia enhances Sympa 6.2.72 for security vulnerabilities. A manual execution is necessary post-update. Essential patches implemented.. Mageia Security Update, Sympa Bug Fix, Mageia Advisory, Sympa Security, Open Source Fix. . Severity: Critical. LinuxSecurity.com Team
Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-271b912b2b 2023-06-11 02:01:36.946071 --------------------------------------------------------------------------------Name : sympa Product : Fedora 38 Version : 6.2.72 Release : 2.fc38 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 1 2023 Xavier Bachelot 6.2.72-1 - Update to 6.2.72 (fixes CVE-2021-4243) - Convert License: to SPDX --------------------------------------------------------------------------------References: [ 1 ] Bug #2156473 - CVE-2021-4243 sympa: jquery-minicolors: potential XSS when using untrusted code for swatch names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2156473 [ 2 ] Bug #2171951 - CVE-2021-32850 sympa: jquery-minicolors: cross-site scripting when handling untrusted color names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2171951 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-271b912b2b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-419ca55dd3 2023-06-11 01:58:02.674345 --------------------------------------------------------------------------------Name : sympa Product : Fedora 37 Version : 6.2.72 Release : 2.fc37 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 1 2023 Xavier Bachelot 6.2.72-1 - Update to 6.2.72 (fixes CVE-2021-4243) - Convert License: to SPDX * Sat Jan 21 2023 Fedora Release Engineering - 6.2.70-2.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2156473 - CVE-2021-4243 sympa: jquery-minicolors: potential XSS when using untrusted code for swatch names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2156473 [ 2 ] Bug #2171951 - CVE-2021-32850 sympa: jquery-minicolors: cross-site scripting when handling untrusted color names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2171951 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-419ca55dd3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to 6.2.60 Fixes CVE-2020-29668. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-11cb6626e2 2021-01-13 01:58:21.870854 --------------------------------------------------------------------------------Name : sympa Product : Fedora 33 Version : 6.2.60 Release : 1.fc33 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to 6.2.60 Fixes CVE-2020-29668 --------------------------------------------------------------------------------ChangeLog: * Mon Jan 4 2021 Xavier Bachelot 6.2.60-1 - Update to 6.2.60 - Fixes CVE-2020-29668 (RHBZ#1906576) * Sat Nov 7 2020 Xavier Bachelot 6.2.58-2 - Add BR: perl-Test-Net-LDAP - Remove all of EL6 thus sysvinit support --------------------------------------------------------------------------------References: [ 1 ] Bug #1906577 - CVE-2020-29668 sympa: allows remote attackers to obtain full SOAP API access via illegal cookie [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1906577 [ 2 ] Bug #1906578 - CVE-2020-29668 sympa: allows remote attackers to obtain full SOAP API access via illegal cookie [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1906578 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c'dnf upgrade --advisory FEDORA-2021-11cb6626e2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.