CVE-2018-1000550
published 2018-06-26CVE-2018-1000550: The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can…
PriorityP351critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.58%
83.4th percentile
The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to be exploitable via HTTP GET/POST request. This vulnerability appears to have been fixed in 6.2.32.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | sympa | < sympa 6.2.32~dfsg-1 (bookworm) | sympa 6.2.32~dfsg-1 (bookworm) |
| sympa | sympa | < 6.2.32 | 6.2.32 |
| sympa | sympa | >= 0 < 6.2.32~dfsg-1 | 6.2.32~dfsg-1 |
| sympa | sympa | >= 0 < 6.2.32~dfsg-1 | 6.2.32~dfsg-1 |
| sympa | sympa | >= 0 < 6.2.32~dfsg-1 | 6.2.32~dfsg-1 |
| sympa | sympa | >= 0 < 6.2.32~dfsg-1 | 6.2.32~dfsg-1 |
| sympa | sympa | >= 0 < 6.1.17~dfsg-1ubuntu0.1~esm1 | 6.1.17~dfsg-1ubuntu0.1~esm1 |
| sympa | sympa | >= 0 < 6.1.24~dfsg-1ubuntu0.1~esm1 | 6.1.24~dfsg-1ubuntu0.1~esm1 |
| sympa | sympa | >= 0 < 6.2.24~dfsg-1ubuntu0.1~esm1 | 6.2.24~dfsg-1ubuntu0.1~esm1 |
| sympa | sympa | >= 0 < 6.2.40~dfsg-4ubuntu0.20.04.1~esm1 | 6.2.40~dfsg-4ubuntu0.20.04.1~esm1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Sympa vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 9.8
CVE-2018-1000550 [CRITICAL] Sympa vulnerabilities
Title: Sympa vulnerabilities
Summary: Several security issues were fixed in Sympa.
USN-4442-1 fixed vulnerabilities in Sympa. This update provides the
corresponding updates for Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu
20.04 ESM. Original advisory details:
Nicolas Chatelain discovered that Sympa incorrectly handled environment
variables. An attacker could possibly use this issue with a setuid
binary and gain root privileges. (CVE-2020-10936)
Michael Kaczmarczik discovered that Sympa incorrectly handled HTTP
GET/POST requests. An attacker could possibly use this issue to insert,
edit or obtain sensitive information. This issue only affected Ubuntu 16.04
ESM and Ubuntu 18.04 ESM. (CVE-2018-1000550)
It was discovered that Sympa incorrectly handled URL parameters. An
attacker could po
Ubuntu
Sympa vulnerabilities
vendor_ubuntu·2020-07-28·CVSS 9.8
CVE-2020-10936 [CRITICAL] Sympa vulnerabilities
Title: Sympa vulnerabilities
Summary: sympa vulnerabilities
Michael Kaczmarczik discovered that Sympa incorrectly handled HTTP
GET/POST requests. An attacker could possibly use this issue to insert,
edit or obtain sensitive information. (CVE-2018-1000550)
It was discovered that Sympa incorrectly handled URL parameters. An
attacker could possibly use this issue to perform XSS attacks.
(CVE-2018-1000671)
Nicolas Chatelain discovered that Sympa incorrectly handled environment
variables. An attacker could possibly use this issue with a setuid
binary and gain root privileges. (CVE-2020-10936)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-1000550: sympa - The Sympa Community Sympa version prior to version 6.2.32 contains a Directory T...
vendor_debian·2018·CVSS 9.8
CVE-2018-1000550 [CRITICAL] CVE-2018-1000550: sympa - The Sympa Community Sympa version prior to version 6.2.32 contains a Directory T...
The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to be exploitable via HTTP GET/POST request. This vulnerability appears to have been fixed in 6.2.32.
Scope: local
bookworm: resolved (fixed in 6.2.32~dfsg-1)
bullseye: resolved (fixed in 6.2.32~dfsg-1)
forky: resolved (fixed in 6.2.32~dfsg-1)
sid: resolved (fixed in 6.2.32~dfsg-1)
trixie: resolved (fixed in 6.2.32~dfsg-1)
GHSA
GHSA-4fwc-r99f-85f4: The Sympa Community Sympa version prior to version 6
ghsa_unreviewed·2022-05-13
CVE-2018-1000550 [CRITICAL] CWE-22 GHSA-4fwc-r99f-85f4: The Sympa Community Sympa version prior to version 6
The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to be exploitable via HTTP GET/POST request. This vulnerability appears to have been fixed in 6.2.32.
OSV
sympa vulnerabilities
osv·2021-03-15·CVSS 9.8
CVE-2020-10936 [CRITICAL] sympa vulnerabilities
sympa vulnerabilities
USN-4442-1 fixed vulnerabilities in Sympa. This update provides the
corresponding updates for Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu
20.04 ESM. Original advisory details:
Nicolas Chatelain discovered that Sympa incorrectly handled environment
variables. An attacker could possibly use this issue with a setuid
binary and gain root privileges. (CVE-2020-10936)
Michael Kaczmarczik discovered that Sympa incorrectly handled HTTP
GET/POST requests. An attacker could possibly use this issue to insert,
edit or obtain sensitive information. This issue only affected Ubuntu 16.04
ESM and Ubuntu 18.04 ESM. (CVE-2018-1000550)
It was discovered that Sympa incorrectly handled URL parameters. An
attacker could possibly use this issue to perform XSS attacks. This issue only
OSV
sympa vulnerabilities
osv·2020-07-28·CVSS 9.8
CVE-2018-1000550 [CRITICAL] sympa vulnerabilities
sympa vulnerabilities
Michael Kaczmarczik discovered that Sympa incorrectly handled HTTP
GET/POST requests. An attacker could possibly use this issue to insert,
edit or obtain sensitive information. (CVE-2018-1000550)
It was discovered that Sympa incorrectly handled URL parameters. An
attacker could possibly use this issue to perform XSS attacks.
(CVE-2018-1000671)
Nicolas Chatelain discovered that Sympa incorrectly handled environment
variables. An attacker could possibly use this issue with a setuid
binary and gain root privileges. (CVE-2020-10936)
OSV
CVE-2018-1000550: The Sympa Community Sympa version prior to version 6
osv·2018-06-26·CVSS 9.8
CVE-2018-1000550 [CRITICAL] CVE-2018-1000550: The Sympa Community Sympa version prior to version 6
The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to be exploitable via HTTP GET/POST request. This vulnerability appears to have been fixed in 6.2.32.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2018/07/msg00033.htmlhttps://sympa-community.github.io/security/2018-001.htmlhttps://usn.ubuntu.com/4442-1/https://www.debian.org/security/2018/dsa-4285https://lists.debian.org/debian-lts-announce/2018/07/msg00033.htmlhttps://sympa-community.github.io/security/2018-001.htmlhttps://usn.ubuntu.com/4442-1/https://www.debian.org/security/2018/dsa-4285
2018-06-26
Published