CVE-2012-2352: High severity sympa vulnerability
The archive management (arcmanage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) doarcmanage, (2) doarcdownload, or (3) doarcdelete functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2352?
CVE-2012-2352 is classified as a high-severity vulnerability due to its potential for unauthorized access and data manipulation.
How do I fix CVE-2012-2352?
To fix CVE-2012-2352, upgrade to Sympa version 6.1.11 or later, which includes a patch that checks permissions.
What types of actions can attackers perform due to CVE-2012-2352?
Attackers can list, read, and delete arbitrary list archives using the vulnerable functions affected by CVE-2012-2352.
Which versions of Sympa are affected by CVE-2012-2352?
CVE-2012-2352 affects all versions of Sympa before 6.1.11.
Is there any workaround for CVE-2012-2352 if I cannot immediately upgrade?
A temporary workaround for CVE-2012-2352 may involve restricting access to the archive management page, but upgrading is strongly recommended.