UbuntuUpdates.org

Package "mailman"

Name: mailman

Description:

Web-based mailing list manager (legacy branch)

Latest version: 1:2.1.26-1ubuntu0.6
Release: bionic (18.04)
Level: updates
Repository: main
Homepage: http://www.list.org/

Links


Download "mailman"


Other versions of "mailman" in Bionic

Repository Area Version
base main 1:2.1.26-1
security main 1:2.1.26-1ubuntu0.6

Changelog

Version: 1:2.1.26-1ubuntu0.1 2020-04-29 17:07:04 UTC

  mailman (1:2.1.26-1ubuntu0.1) bionic-security; urgency=medium

  * SECURITY UPDATE: XSS vulnerability
    - debian/patches/93_CVE-2018-0618.patch: avoiding
      injections in Mailman/Gui/General.py, Mailman/Utils.py,
      Mailman/Gui/GUIBase.py
    - CVE-2018-0618
  * SECURITY UPDATE: Arbitrary text injection
    - debian/patches/94_CVE-2018-13796.patch: check for injections
      in Mailmain/Utils.py.
    - CVE-2018-13796
  * SECURITY UPDATE: XSS vulnerability
    - debian/patches/CVE-2020-12137.diff: use .bin extension
      for scrubbed application/octet-stream files in
      Mailman/Handlers/Scrubber.py.
    - CVE-2020-12137

 -- <email address hidden> (Leonidas S. Barbosa) Tue, 28 Apr 2020 15:41:09 -0300

CVE-2018-0618 Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via uns
CVE-2018-13796 An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.
CVE-2020-12137 GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks a



About   -   Send Feedback to @ubuntu_updates