Bug#672859: wwsympa.fcgi fails to check download/delete permissions properly

2012-05-14 Thread George Kargiotakis
Package: sympa Version: 6.0.1+dfsg-4 Severity: grave Sympa versions 6.1.11 have a severe security issue where any user can download or delete the archives of a mailing list if they know the name of the list. Debian has been tracking it at http://security-tracker.debian.org/tracker/CVE-2012-2352

Bug#672859: wwsympa.fcgi fails to check download/delete permissions properly

2012-05-14 Thread David Verdin
Hi, and thanks for reporting this problem to the Debian tracking system. Upgrading the package to 6.0.7 will also fix the problem. Cheers, David Le 14/05/12 11:15, George Kargiotakis a écrit : Package: sympa Version: 6.0.1+dfsg-4 Severity: grave Sympa versions6.1.11 have a severe security