debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sympa | Sympa | * | 6.2.40 (excluding) |
Sympa | Ubuntu | bionic | * |
Sympa | Ubuntu | esm-apps/bionic | * |
Sympa | Ubuntu | esm-apps/focal | * |
Sympa | Ubuntu | esm-apps/jammy | * |
Sympa | Ubuntu | esm-apps/xenial | * |
Sympa | Ubuntu | focal | * |
Sympa | Ubuntu | groovy | * |
Sympa | Ubuntu | hirsute | * |
Sympa | Ubuntu | impish | * |
Sympa | Ubuntu | jammy | * |
Sympa | Ubuntu | kinetic | * |
Sympa | Ubuntu | trusty | * |
Sympa | Ubuntu | upstream | * |
Sympa | Ubuntu | xenial | * |