Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.
| Software | From | Fixed in |
|---|---|---|
| sympa / sympa | 6.2.57-beta1 | 6.2.57-beta1.x |
| sympa / sympa | 6.2.57-beta2 | 6.2.57-beta2.x |
| sympa / sympa | - | 6.2.56.x |
| fedoraproject / fedora | 32 | 32.x |
| fedoraproject / fedora | 33 | 33.x |
| fedoraproject / fedora | 34 | 34.x |
| debian / debian_linux | 9.0 | 9.0.x |