Fedora has issued an advisory on August 7: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QMI7UFFD7ZLOTUTAKJZPPN6H6ME47ECQ/ The issue is fixed upstream in 2.1.28 (2.1.29 is the latest). Mageia 5 and Mageia 6 are also affected.
Whiteboard: (none) => MGA6TOO
Assigning to the registered maintainer.
Assignee: bugsquad => mramboCC: (none) => marja11
Updated package uploaded for cauldron and Mageia 6. Advisory: ======================== Updated mailman package fixes security vulnerability: It was discovered that mailman prior to 2.1.29 mishandled URLs in Utils.py:GetPathPieces() which allowed attackers to display arbitrary text on trusted sites (CVE-2018-13796). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-13796 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QMI7UFFD7ZLOTUTAKJZPPN6H6ME47ECQ/ ======================== Updated packages in core/updates_testing: ======================== mailman-2.1.29-1.mga6 from mailman-2.1.29-1.mga6.src.rpm Testing procedure https://bugs.mageia.org/show_bug.cgi?id=22550#c5
Assignee: mrambo => qa-bugsVersion: Cauldron => 6Whiteboard: MGA6TOO => (none)Keywords: (none) => has_procedure
MGA6-32 MATE on IBM Thinkpad R50e No installation issues Following procedure given above, at CLI (after checking httpd is running): # list_lists 1 matching mailing lists found: Mailman - Mailman site list # newlist --quiet --urlhost=localhost.localdomain --emailhost=localhost.localdomain test hviaene@gmail.com Initial test password: postalias: warning: inet_protocols: disabling IPv6 name/address support: Address family not supported by protocol # list_lists 2 matching mailing lists found: Mailman - Mailman site list Test - [geen omschrijving beschikbaar] # list_owners hviaene@gmail.com root@<myFQDN> Ensured the web interface available at http://localhost/mailman # rmlist test Not removing archives. Reinvoke with -a to remove them. postalias: warning: inet_protocols: disabling IPv6 name/address support: Address family not supported by protocol Removing list info # list_lists 1 matching mailing lists found: Mailman - Mailman site list # list_owners root@<myFQDN> Looks all OK to me
Whiteboard: (none) => MGA6-32-OKCC: (none) => herman.viaene
Keywords: (none) => advisoryCC: (none) => tmb
Installed 64-bit mailman + dependencies, then updated the mailman package. All packages installed cleanly. Using Herman's tests to verify operation. Validating.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0383.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED