mailman (1:2.1.20-1ubuntu0.5) xenial-security; urgency=medium
* SECURITY UPDATE: Arbitrary Content Injection
- debian/patches/CVE-2020-12108.diff: removed
safeusers variable that allows arbitrary content
to be injected in Mailman/Cgi/options.py.
- CVE-2020-12108
Date: 2020-05-07 13:23:38.779997+00:00
Changed-By: [email protected] (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/mailman/1:2.1.20-1ubuntu0.5
Sorry, changesfile not available.
--
Xenial-changes mailing list
[email protected]
Modify settings or unsubscribe at:
https://lists.ubuntu.com/mailman/listinfo/xenial-changes