First published: Wed Oct 07 2020(Updated: )
Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sympa Sympa | <=6.2.56 | |
Sympa Sympa | =6.2.57-beta1 | |
Sympa Sympa | =6.2.57-beta2 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Debian Debian Linux | =9.0 | |
debian/sympa | <=6.2.60~dfsg-4<=6.2.70~dfsg-2<=6.2.72~dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.