• [SECURITY] [DSA 4664-1] mailman security update

    From Thijs Kinkhorst@1:229/2 to All on Sun Apr 26 14:10:01 2020
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA256

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4664-1 [email protected] https://www.debian.org/security/ Thijs Kinkhorst
    April 26, 2020 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : mailman
    CVE ID : CVE-2020-12137

    Hanno Boeck discovered that it was possible to create a cross site
    scripting attack on the webarchives of the Mailman mailing list manager,
    by sending a special type of attachement.

    For the oldstable distribution (stretch), this problem has been fixed
    in version 1:2.1.23-1+deb9u5.

    For the stable distribution (buster), this problem has been fixed in
    version 1:2.1.29-1+deb10u1.

    We recommend that you upgrade your mailman packages.

    For the detailed security status of mailman please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/mailman

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQEzBAEBCAAdFiEEeANVtepr/II1qZxLVvYaeUAdrAQFAl6ldoAACgkQVvYaeUAd rAQyJQgAjxK8M4ft/4GjtlgdogGUORooPfaAAQojLNnF3OLf7VqysmThOdOgL2vK ZDd6d543zPK1/UARUS/Ajh+gpkKa/aNV1Ug7Duo18joeXnnFDUIbsuyAx0K86zAQ Uus1+hdoRI+TG+tI9fkNkrU82F5ki9tcsr8oy20AI/iiaTR+xFm18a/LtrykH9a/ S9+iqrpu/6Pb3Bk8CNUQI/iwhNsbMEQ3x2BxuQW/6jttnNyJNhXgs6XNSlCGraQh 7DdAMGKQYxMGm3blFwj2JTDYoJF4jDnwDnifr1gEKx3ZthmschufrqhCBG1cE8W+ VSttcXsYJoahvl0WUfuiuQEweZnuaA==
    =7eIC
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)