[ubuntu/bionic-security] mailman 1:2.1.26-1ubuntu0.5 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Thu Nov 18 14:07:24 UTC 2021


mailman (1:2.1.26-1ubuntu0.5) bionic-security; urgency=medium

  * SECURITY UPDATE: XSS vulnerability
    - debian/patches/CVE-2021-43331.patch: sanitize URL from user
      option page in Mailman/Cgi/options.py.
    - CVE-2021-43331
  * SECURITY UPDATE: CSRF attack
    - debian/patches/CVE-2021-43332.patch: checks authorizations
      in Mailman/CSRFcheck.py, Mailman/Cgi/admindb.py.
    - CVE-2021-43332

Date: 2021-11-17 15:30:14.166263+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/mailman/1:2.1.26-1ubuntu0.5
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list