Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-88ad2bee84 2024-12-26 01:20:11.418870+00:00 -------------------------------------------------------------------------------- Name : sympa Product : Fedora 41 Version : 6.2.74 Release : 1.fc41 URL : http://www.sympa.org Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. -------------------------------------------------------------------------------- Update Information: Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 16 2024 Xavier Bachelot - 6.2.74-1 - Update to 6.2.74, fix for CVE-2024-55919 - Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-88ad2bee84' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-14c006b8bb 2024-12-25 01:38:03.924476+00:00 -------------------------------------------------------------------------------- Name : sympa Product : Fedora 40 Version : 6.2.74 Release : 1.fc40 URL : http://www.sympa.org Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. -------------------------------------------------------------------------------- Update Information: Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 16 2024 Xavier Bachelot - 6.2.74-1 - Update to 6.2.74, fix for CVE-2024-55919 - Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-14c006b8bb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Sympa 6.2.72 fixes many bugs, including the security one related in CVE-2021-32850 It is required to manually run sympa upgrade after get this update References: . MGASA-2024-0052 - Updated sympa packages fix security vulnerabilities Publication date: 29 Feb 2024 URL: https://advisories.mageia.org/MGASA-2024-0052.html Type: security Affected Mageia releases: 9 CVE: CVE-2021-32850 Sympa 6.2.72 fixes many bugs, including the security one related in CVE-2021-32850 It is required to manually run sympa upgrade after get this update References: - https://bugs.mageia.org/show_bug.cgi?id=32896 - https://github.com/sympa-community/sympa/releases/tag/6.2.72 - https://www.cve.org/CVERecord?id=CVE-2021-32850 - https://www.cve.org/CVERecord?id=CVE-2021-32850 SRPMS: - 9/core/sympa-6.2.72-4.mga9 . Mageia enhances Sympa 6.2.72 for security vulnerabilities. A manual execution is necessary post-update. Essential patches implemented.. Mageia Security Update, Sympa Bug Fix, Mageia Advisory, Sympa Security, Open Source Fix. . Severity: Critical. LinuxSecurity.com Team
Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-271b912b2b 2023-06-11 02:01:36.946071 --------------------------------------------------------------------------------Name : sympa Product : Fedora 38 Version : 6.2.72 Release : 2.fc38 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 1 2023 Xavier Bachelot 6.2.72-1 - Update to 6.2.72 (fixes CVE-2021-4243) - Convert License: to SPDX --------------------------------------------------------------------------------References: [ 1 ] Bug #2156473 - CVE-2021-4243 sympa: jquery-minicolors: potential XSS when using untrusted code for swatch names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2156473 [ 2 ] Bug #2171951 - CVE-2021-32850 sympa: jquery-minicolors: cross-site scripting when handling untrusted color names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2171951 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-271b912b2b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-419ca55dd3 2023-06-11 01:58:02.674345 --------------------------------------------------------------------------------Name : sympa Product : Fedora 37 Version : 6.2.72 Release : 2.fc37 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 1 2023 Xavier Bachelot 6.2.72-1 - Update to 6.2.72 (fixes CVE-2021-4243) - Convert License: to SPDX * Sat Jan 21 2023 Fedora Release Engineering - 6.2.70-2.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2156473 - CVE-2021-4243 sympa: jquery-minicolors: potential XSS when using untrusted code for swatch names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2156473 [ 2 ] Bug #2171951 - CVE-2021-32850 sympa: jquery-minicolors: cross-site scripting when handling untrusted color names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2171951 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-419ca55dd3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to 6.2.60 Fixes CVE-2020-29668. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-11cb6626e2 2021-01-13 01:58:21.870854 --------------------------------------------------------------------------------Name : sympa Product : Fedora 33 Version : 6.2.60 Release : 1.fc33 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to 6.2.60 Fixes CVE-2020-29668 --------------------------------------------------------------------------------ChangeLog: * Mon Jan 4 2021 Xavier Bachelot 6.2.60-1 - Update to 6.2.60 - Fixes CVE-2020-29668 (RHBZ#1906576) * Sat Nov 7 2020 Xavier Bachelot 6.2.58-2 - Add BR: perl-Test-Net-LDAP - Remove all of EL6 thus sysvinit support --------------------------------------------------------------------------------References: [ 1 ] Bug #1906577 - CVE-2020-29668 sympa: allows remote attackers to obtain full SOAP API access via illegal cookie [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1906577 [ 2 ] Bug #1906578 - CVE-2020-29668 sympa: allows remote attackers to obtain full SOAP API access via illegal cookie [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1906578 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c'dnf upgrade --advisory FEDORA-2021-11cb6626e2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several vulnerabilities were discovered in Sympa, a mailing list manager, which could result in local privilege escalation, denial of service or unauthorized access via the SOAP API. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4818-1
Sympa, a modern mailing list manager, grants full SOAP API access by sending invalid string as the cookie value, if the SOAP endpoint was enabled. An attacker could manipulate the mailing lists, including subscribing e-mails or getting the list of subscribers. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2499-1
Get the latest Linux and open source security news straight to your inbox.