Information disclosure in Sympa - CVE-2015-1306
Published: January 22, 2015 / Updated: August 9, 2020
Vulnerability identifier: #VU40929
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2015-1306
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: sympa.org
Affected software:
Sympa
Sympa
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors.
How to mitigate CVE-2015-1306
Install update from vendor's website.
Sources
- http://advisories.mageia.org/MGASA-2015-0085.html
- http://secunia.com/advisories/62387
- http://secunia.com/advisories/62442
- http://www.debian.org/security/2015/dsa-3134
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:051
- http://www.openwall.com/lists/oss-security/2015/01/20/4
- http://www.securityfocus.com/bid/72277
- https://www.sympa.org/security_advisories