FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

sympa -- Remote attackers can read arbitrary files

Affected packages
sympa < 6.1.24

Details

VuXML ID 451a6c79-c92b-11e4-a835-000c292ee6b8
Discovery 2015-01-13
Entry 2015-03-13

The Sympa Project reports:

The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors.

References

CVE Name CVE-2015-1306
URL https://www.sympa.org/security_advisories