vulnerability

FreeBSD: VID-31a7ffb1-a80a-11eb-b159-f8b156c2bfe9: sympa -- Inappropriate use of the cookie parameter can be a security threat. This parameter may also not provide sufficient security.

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
Published
Apr 27, 2021
Added
Nov 4, 2022
Modified
Dec 10, 2025

Description

Earlier versions of Sympa require a parameter named cookie in sympa.conf configuration file. This parameter was used to make some identifiers generated by the system unpredictable. For example, it was used as following: To be used as a salt to encrypt passwords stored in the database by the RC4 symmetric key algorithm. Note that RC4 is no longer considered secure enough and is not supported in the current version of Sympa. To prevent attackers from sending crafted messages to achieve XSS and so on in message archives. There were the following problems with the use of this parameter. This parameter, for its purpose, should be different for each installation, and once set, it cannot be changed. As a result, some sites have been operating without setting this parameter. This completely invalidates the security measures described above. Even if this parameter is properly set, it may be considered not being strong enough against brute force attacks.

Solution

freebsd-upgrade-package-sympa

References

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.