Bug#961491: CVE-2020-10936: Security flaws in setuid wrappers

2020-12-14 Thread Sylvain Beucler
On 07/12/2020 12:06, Stefan Hornburg (Racke) wrote: On 12/7/20 10:52 AM, Sylvain Beucler wrote: This high-severity issue was marked with: [buster] - sympa (Will be fixed via point release) Consequently I am surprised that it wasn't part of last week's Debian 10.7 point release. What

Bug#961491: CVE-2020-10936: Security flaws in setuid wrappers

2020-12-07 Thread Stefan Hornburg (Racke)
On 12/7/20 10:52 AM, Sylvain Beucler wrote: > Hi, > > On Sat, 10 Oct 2020 09:45:42 +0300 "Stefan Hornburg (Racke)" > wrote: >> On 10/7/20 3:03 PM, Sylvain Beucler wrote: >> > I noticed this local root escalation yesterday and I'm working on a >> > Stretch LTS update. >> > See also

Bug#961491: CVE-2020-10936: Security flaws in setuid wrappers

2020-12-07 Thread Sylvain Beucler
Hi, On Sat, 10 Oct 2020 09:45:42 +0300 "Stefan Hornburg (Racke)" wrote: On 10/7/20 3:03 PM, Sylvain Beucler wrote: > I noticed this local root escalation yesterday and I'm working on a > Stretch LTS update. > See also https://salsa.debian.org/sympa-team/sympa/-/merge_requests/1 > > Are there

Bug#961491: CVE-2020-10936: Security flaws in setuid wrappers

2020-05-25 Thread Stefan Hornburg (Racke)
package: sympa severity: critical tags: upstream security patch Security advisory: https://sympa-community.github.io/security/2020-002.html Excerpt: --snip-- A vulnerability has been discovered in Sympa web interface by which attacker can execute arbitrary code with root privileges. Sympa