Vulnerability Description
Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sympa | Sympa | >= 6.2.38, <= 6.2.52 |
| Fedoraproject | Fedora | 30 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://github.com/sympa-community/sympa/issues/886Issue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://sympa-community.github.io/security/2020-001.htmlPatchThird Party Advisory
- https://www.debian.org/security/2020/dsa-4818Third Party Advisory
- https://github.com/sympa-community/sympa/issues/886Issue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://sympa-community.github.io/security/2020-001.htmlPatchThird Party Advisory
- https://www.debian.org/security/2020/dsa-4818Third Party Advisory
FAQ
What is CVE-2020-9369?
CVE-2020-9369 is a vulnerability with a CVSS score of 7.5 (HIGH). Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malf...
How severe is CVE-2020-9369?
CVE-2020-9369 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9369?
Check the references section above for vendor advisories and patch information. Affected products include: Sympa Sympa, Fedoraproject Fedora, Debian Debian Linux.