openSUSE has issued an advisory today (June 30): https://lists.opensuse.org/opensuse-updates/2018-06/msg00147.html The issue is fixed upstream in 2.1.27. Mageia 5 and Mageia 6 are also affected.
Whiteboard: (none) => MGA6TOO
Assigning to the registered maintainer.
CC: (none) => marja11Assignee: bugsquad => mrambo
Updated packages built for cauldron and Mageia 6. Advisory: ======================== Updated mailman package fixes security vulnerability: It was discovered that mailman version prior to 2.1.27 contained a vulnerability where malicious list owners could inject evil scripts into listinfo pages (CVE-2018-0618). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-0618 https://lists.opensuse.org/opensuse-updates/2018-06/msg00147.html https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-0618.html ======================== Updated packages in core/updates_testing: ======================== mailman-2.1.27-1.mga6.x86_64.rpm from mailman-2.1.27-1.mga6.src.rpm Testing procedure https://bugs.mageia.org/show_bug.cgi?id=22550#c5
Version: Cauldron => 6Assignee: mrambo => qa-bugsKeywords: (none) => has_procedureWhiteboard: MGA6TOO => (none)
MGA6-32 on IBM Thinkpad R50e MATE No installation issues. Running test as indicated above is all OK, but to be more complete: - make sure httpd is running - run the commands from bug 22550 but make sure that the newlist command is complete - last part of it is on the second line. - before trying to run the webinterface, do # systemctl start mailman - to get to your testlist point to http://localhost/mailman/listinfo.cgi/test and click below on "Test administrative interface" to get further. All works OK.
Whiteboard: (none) => MGA6-32-OKCC: (none) => herman.viaene
Advisory committed to svn. Validating the update.
Keywords: (none) => advisory, validated_updateCC: (none) => davidwhodgins, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0313.html
Status: NEW => RESOLVEDResolution: (none) => FIXED