FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-2352

This CVE name corresponds to:

Entered Topic
2012-05-21 sympa -- Multiple Security Bypass Vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-2352
Phase Assigned(20120419)

Description

The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) do_arc_download, or (3) do_arc_delete functions.

References

Source Reference
MLIST [oss-security] 20120511 CVE request: sympa (try again)
MLIST [oss-security] 20120511 Re: CVE request: sympa (try again)
MLIST [oss-security] 20120512 Re: CVE request: sympa (try again)
CONFIRM https://sourcesup.renater.fr/scm/viewvc.php/branches/sympa-6.0-branch/wwsympa/wwsympa.fcgi.in?root=sympa&r1=6706&r2=7358&pathrev=7358
CONFIRM https://www.sympa.org/distribution/latest-stable/NEWS
DEBIAN DSA-2477
BID 53503
OSVDB 81890
SECUNIA 49045
SECUNIA 49237