Bug#888201: mailman: CVE-2018-5950

2018-02-04 Thread Salvatore Bonaccorso
Control: found -1 1:2.1.18-1 On Thu, Feb 01, 2018 at 01:46:05PM +0100, Thijs Kinkhorst wrote: > >> I plan to release Mailman 2.1.26 along with a patch for older releases > >> to fix this issue on Feb 4, 2018. At that time, full details of the > >> vulnerability will be public. > > I've reserved

Bug#888201: mailman: CVE-2018-5950

2018-02-01 Thread Thijs Kinkhorst
>> I plan to release Mailman 2.1.26 along with a patch for older releases >> to fix this issue on Feb 4, 2018. At that time, full details of the >> vulnerability will be public. I've reserved time on Sunday to in any case to sid when the fix is released, and depending on the details/severity look

Bug#888201: mailman: CVE-2018-5950

2018-01-23 Thread Salvatore Bonaccorso
Source: mailman Version: 1:2.1.25-1 Severity: grave Tags: security upstream Hi, the following vulnerability was published for mailman, filling for now as grave since no details on the impact nor the fix is public, cf. [1], where it states: > An XSS vulnerability in the Mailman 2.1 web UI has