lp:ubuntu/edgy-security/mailman
- Get this branch:
- bzr branch lp:ubuntu/edgy-security/mailman
Branch merges
Branch information
Recent revisions
- 11. By Emanuele Gentili
-
* SECURITY UPDATE:
+ debian/patches/ 100_CVE- 2008-0564. dpatch (LP: #199338)
- Multiple cross-site scripting (XSS) vulnerabilities in Mailman
before 2.1.10b1 allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors related to (1) editing
templates and (2) the list's "info attribute" in the web
administrator interface.
* References
+ http://cve.mitre. org/cgi- bin/cvename. cgi?name= CVE-2008- 0564
+ http://bugs.gentoo. org/show_ bug.cgi? id=208710 - 10. By Martin Pitt
-
* SECURITY UPDATE: XSS.
* Add debian/patches/ security- CVE-2006- 3636-XSS. dpatch:
- Fix various cross-site scripting vulnerabilities.
- Patch backported from svn head, thanks to Barry Warsaw for preparing it.
- CVE-2006-3636
* Add debian/patches/ security- CVE-2006- 2941.dpatch:
- Scrubber.py: Do not bail out if emails' get_filename() throws a
ValueError. This has been properly fixed in the next upstream email
package (in Python core), but the fix is very intrusive. Thanks to Steve
Alexander for discovering this and for the proposed patch.
- CVE-2006-2941
- Closes: LP#49620
* Add debian/patches/ security- error_log. dpatch:
- Check characters in URL to prevent injecting bogus messages into
error_log.
- Patch taken from upstream SVN:
http://svn.sourceforge .net/viewvc/ mailman? view=rev& revision= 7918 - 9. By Martin Pitt
-
Merge new Debian revision; Debian adopted the init script and apache2
dependency fix, only remaining diff is the exim4->postfix dependency
change. - 8. By Martin Pitt
-
* Merge to Debian; remaining Ubuntu changes:
- debian/mailman. init: Create /var/{run, lock}/mailman.
- debian/control: exim4 -> postfix.
* debian/control: Dependency fix: apache -> apache2. - 7. By Martin Pitt
-
* Security update: Remote DoS.
* Add debian/patches/ 72_mime_ None_payload. dpatch:
- Do not crash if python's email module returns None for the payload of a
MIME part. This can happen for message/delivery- status or parts that
contain only two blank lines.
- See upstream bug reports and CVS patch:
https://sourceforge. net/tracker/ ?func=detail& atid=100103& aid=1430236& group_id= 103
https://sourceforge. net/tracker/ ?func=detail& atid=100103& aid=1099138& group_id= 103
http://cvs.sourceforge .net/viewcvs. py/mailman/ mailman/ Mailman/
Handlers/Scrubber. py?r1=2. 18.2.22& r2=2.18. 2.23&diff_ format= u
* CVE-2006-0052 - 6. By Tollef Fog Heen
-
Create /var/run/mailman and /var/lock/mailman if they're missing.
Part of the New World Order with those being tmpfs-es. Malone #33749 - 5. By Martin Pitt
-
* SECURITY UPDATE: Remote DoS.
* Add debian/patches/ 70_invalid_ utf8_dos. dpatch:
- Do not crash on attachment filenames with invalid UTF-8 encoded name.
- Thanks to Lionel Elie Mamane <email address hidden> for preparing the
patch.
- CVE-2005-3573
* Add debian/patches/ 71_invalid_ date_dos. dpatch:
- Do not crash on mails with specially crafted dates which generate an
OverflowError exception.
- CVE-2005-4153 - 3. By Tollef Fog Heen
-
Fix up time.strftime call in bounce handling to conform to how time in
python 2.4 wants it. Ubuntu #17183 - 2. By Tollef Fog Heen <email address hidden>
-
* Brown bag release -- use '/' instead of the undefined SLASH in
Cgi/private.py. (closes: #294874)
* Handle the case of non-ascii chars in realname. (closes: #293861)
* Fix up typo in cron script (closes: #284311)
* Use head -n 1 instead of cat for getting the mailname out of
/etc/mailname. (closes: #287636)
Branch metadata
- Branch format:
- Branch format 7
- Repository format:
- Bazaar repository format 2a (needs bzr 1.16 or later)
- Stacked on:
- lp:ubuntu/karmic/mailman