CVE-2020-9369: Debian Linux

High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.

Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
  • Sympa Sympa: from 6.2.38, up to and including 6.2.52

Published 2020-02-24. Last modified 2026-06-17.