Package "mailman"
Name: |
mailman
|
Description: |
Web-based mailing list manager (legacy branch)
|
Latest version: |
1:2.1.26-1ubuntu0.6 |
Release: |
bionic (18.04) |
Level: |
updates |
Repository: |
main |
Homepage: |
http://www.list.org/ |
Links
Download "mailman"
Other versions of "mailman" in Bionic
Changelog
mailman (1:2.1.26-1ubuntu0.1) bionic-security; urgency=medium
* SECURITY UPDATE: XSS vulnerability
- debian/patches/93_CVE-2018-0618.patch: avoiding
injections in Mailman/Gui/General.py, Mailman/Utils.py,
Mailman/Gui/GUIBase.py
- CVE-2018-0618
* SECURITY UPDATE: Arbitrary text injection
- debian/patches/94_CVE-2018-13796.patch: check for injections
in Mailmain/Utils.py.
- CVE-2018-13796
* SECURITY UPDATE: XSS vulnerability
- debian/patches/CVE-2020-12137.diff: use .bin extension
for scrubbed application/octet-stream files in
Mailman/Handlers/Scrubber.py.
- CVE-2020-12137
-- <email address hidden> (Leonidas S. Barbosa) Tue, 28 Apr 2020 15:41:09 -0300
|
CVE-2018-0618 |
Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via uns |
CVE-2018-13796 |
An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site. |
CVE-2020-12137 |
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks a |
|
About
-
Send Feedback to @ubuntu_updates