Debian Linux Security Advisory 2073-1 – Florian Streibelt reported a a directory traversal flaw in the way the Mailing List Managing Made Joyful mailing list manager processed users’ requests originating from the administrator web interface without enough input validation. A remote, authenticated attacker could use these flaws to write and / or delete arbitrary files.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/92028/dsa-2073-1.txt
Source: https://packetstormsecurity.com/files/92028/Debian-Linux-Security-Advisory-2073-1.html

