• [SECURITY] [DSA 3668-1] mailman security update

    From Thijs Kinkhorst@1:229/2 to All on Thu Sep 15 14:20:02 2016
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA256

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3668-1 [email protected] https://www.debian.org/security/ Thijs Kinkhorst September 15, 2016 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : mailman
    CVE ID : CVE-2016-6893
    Debian Bug : 835970

    It was discovered that there was a CSRF vulnerability in mailman, a
    web-based mailing list manager, which could allow an attacker to obtain
    a user's password.

    For the stable distribution (jessie), this problem has been fixed in
    version 1:2.1.18-2+deb8u1.

    For the unstable distribution (sid), this problem has been fixed in
    version 1:2.1.23-1.

    We recommend that you upgrade your mailman packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQEcBAEBCAAGBQJX2o9rAAoJEFb2GnlAHawE614H/19mvKKiWGlH4rqQ9wOf0FS7 Vfg/S+P1QDYCFPuoY3lmI7Zlqf47lseKkguI+KL5imS7oN9Anu2uCHEyjvFDSuPQ 0L9fnQA5k+DGoYnW0vpfy1B8pOy4u+3hSCSeKsDvVcwEx0T4KGxIcw9Azcp1xlyI eynNjQUX9Yg6bliVDzHK+ENj9X1xODC290hnWmL576lmOMDStOxkvjEeUkloNkQS TQvgMiOTv9xAaD/poF3TTqOlq2xKMnzllIDwywLGNmw1sGMwVv1wPU+b7j+8HL6z 5NlfjsGM1fkCfvHMaR8NXjeIqpVzyiKzGfjx5OLLibU3+VbFhuiu4GIUtm2Nfy4=
    =s2Tj
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)