First published: Fri Oct 09 2020(Updated: )
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sympa Sympa | <6.2.40 | |
Debian Debian Linux | ||
Debian Debian Linux | =10.0 | |
debian/sympa | <=6.2.40~dfsg-6<=6.2.40~dfsg-1 | |
debian/sympa | 6.2.60~dfsg-4 6.2.70~dfsg-2 6.2.72~dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.