-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 20 Jan 2025 23:56:40 CET Source: sympa Architecture: source Version: 6.2.60~dfsg-4+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Debian Sympa team <sympa@packages.debian.org> Changed-By: Markus Koschany <apo@debian.org> Checksums-Sha1: ce82df3d424b197fc684fc6c9dc916b8ba81eafe 2675 sympa_6.2.60~dfsg-4+deb11u1.dsc 5fd2dc3f9c0ee593895bd89e4664e605b587f571 3817760 sympa_6.2.60~dfsg.orig.tar.xz d08b2a55d06dea20c3f800d7cf1ae4c2805ba925 167812 sympa_6.2.60~dfsg-4+deb11u1.debian.tar.xz 888140d6ed3121f178abaf995cb01572ce8a506b 11762 sympa_6.2.60~dfsg-4+deb11u1_amd64.buildinfo Checksums-Sha256: 5e745e883ebbf1412dd1cfdc9fb090cd0c558644e43a6f2ecb604d5bdd7bd926 2675 sympa_6.2.60~dfsg-4+deb11u1.dsc f5438090868ad6c10ecd84fd9c75a627d9655141b020fbaf645e38e6671c907f 3817760 sympa_6.2.60~dfsg.orig.tar.xz 70b50ae149795e8678dec79023137c1da7af9f24192bad1f753d8eba49187418 167812 sympa_6.2.60~dfsg-4+deb11u1.debian.tar.xz 5cccb7b92530a92b7f0b7e4928fd944452cf0f82e0812922733c1517606b674c 11762 sympa_6.2.60~dfsg-4+deb11u1_amd64.buildinfo Changes: sympa (6.2.60~dfsg-4+deb11u1) bullseye-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2024-55919: A flaw was found in Sympa's web interface, a modern mailing list manager. An attacker may bypass authentication by using an arbitrary e-mail address when the generic SSO loging feature was enabled. Files: 09494c0e0cb2962dd4998525beb5a4cf 2675 mail optional sympa_6.2.60~dfsg-4+deb11u1.dsc ecc0d4de161bd4f6835f23d6e379bac0 3817760 mail optional sympa_6.2.60~dfsg.orig.tar.xz 308b1096500bc1d561de34b5e179d940 167812 mail optional sympa_6.2.60~dfsg-4+deb11u1.debian.tar.xz 92ba45cb9b1710bf2a0aedaedf245f81 11762 mail optional sympa_6.2.60~dfsg-4+deb11u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmeO1LpfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkbC0QALOTpiNQB2aCwWECNUWxeeM0e8wp1AuftjmN CIFIimZP6LEF+j6+WpWaYXK6Vq2OOKdmbwVjY/HMVKpUgPSyJW43ui1l7x7vD+/g dIDkm+FBt+MQTKtMJfFa6jmjP8nsIQBL6R/rASTDLOa7zYH6Md97unS8LoOwif8F ZCCPFQpLoV0uV/dWCdXpmMPdh7ARh7j7d4Z6D6dZ2kwTfYWxbDjLeZ7OcsSg/S8Q JmHyfIaZKFIX+ejtSOCNn6LilON/fhWASEAZp63kyjIgbFfVgj0Qw8CGWhgDGYKN MqP01IB2+IQ5OMNH7m96DfK3TYCO8nvl7xPlgfiAo1Zqjirjg5uwbN96Ysx5Dkha QWITMf+RSMypWJiWn8EmX+fDrScTC6W0lxqs8sudIbB3KZhM/ZBVXwxQ4Vky4KiR FT/GP+pUGOfLAredwWJATej4GcL1HT1qElBiSG4P6RdB1SuHM3xrPlzzwqfDU/ou dDHYLKN90pKK4Yi3n8DgbrwfeNSabVj7zzE+lIrdaB4lr9SgFZnjmEL3G42C733Z u5ltT2A58L0TY/dRugDd9+eG7VX6eXThztFTy+GzbDjUTMLipwKBYFir0uSJJD2B lqclScDV2rSDgQMmbajTGGfSiZLFSaxVkbHtSQNcjaXFqXWDpYOiaQ7//Hu0mgHG ZNPqlAyY =mR9S -----END PGP SIGNATURE-----