-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 03 May 2020 08:17:51 +0200 Source: mailman Binary: mailman Architecture: source amd64 Version: 1:2.1.18-2+deb8u5 Distribution: jessie-security Urgency: medium Maintainer: Mailman for Debian <pkg-mailman-hackers@lists.alioth.debian.org> Changed-By: Anton Gladky <gladk@debian.org> Description: mailman - Powerful, web-based mailing list manager Changes: mailman (1:2.1.18-2+deb8u5) jessie-security; urgency=medium . * Non-maintainer upload by the LTS Security Team. * Fix stored cross site scripting in attachment extensions. Fix CVE-2020-12137 Checksums-Sha1: c2fe16f38c3bd7c2fc8d09e7b817480f6384e2d9 2110 mailman_2.1.18-2+deb8u5.dsc 3ea3aff36984a7ccc92bc784b7e76cb8156fa4fc 9095038 mailman_2.1.18.orig.tar.gz 3bca8100b100ff57c68a01b9ed3d718b597c4e86 108212 mailman_2.1.18-2+deb8u5.debian.tar.xz e9282929ed44e95eeef061761b294219d7c34684 4304338 mailman_2.1.18-2+deb8u5_amd64.deb Checksums-Sha256: 8bad4a3b9697f16d81cd0ffbe7fbab6cae11282deaf8b0802df345ebd1d0cca6 2110 mailman_2.1.18-2+deb8u5.dsc dc1d605321448e7e5e804e26493f7689a0b17f0810505dc3f9774f9519308349 9095038 mailman_2.1.18.orig.tar.gz 3e09be28d06e0c6218b0b73507fc689105c1bc73c31da66b2822f59a98c37ad9 108212 mailman_2.1.18-2+deb8u5.debian.tar.xz b8db4d066b94ee50cfb12ceedc7d82568e9c8bb5c06c4ac72e25f432a3630427 4304338 mailman_2.1.18-2+deb8u5_amd64.deb Files: 686af3d0e59b63285af96bd29d91097d 2110 mail optional mailman_2.1.18-2+deb8u5.dsc 02ce493711248e1d3723356188446d9f 9095038 mail optional mailman_2.1.18.orig.tar.gz 40c43037af9c2869fb79dafc63191ef2 108212 mail optional mailman_2.1.18-2+deb8u5.debian.tar.xz 7d149b33b01e1218357d5826aa0340b0 4304338 mail optional mailman_2.1.18-2+deb8u5_amd64.deb -----BEGIN PGP SIGNATURE----- iQJFBAEBCgAvFiEEu71F6oGKuG/2fnKF0+Fzg8+n/wYFAl6ube8RHGdsYWRrQGRl Ymlhbi5vcmcACgkQ0+Fzg8+n/wYH4g/8DHbU1q6BnyiDG/D8ZVm5LMx34cAYNYRY cnhgXcKWfUaVo5CeZjz0FNqDTtFRgmvpbpPlTCOF2jykTHNrxH+uk8xf9LRCbPLp cx1Pq0TEBE9Z8+y9l07ULJbQoUhh0QNfEXBhzDTAu51ehOezrnzDpRhMn33V9D5u 3GdUOXeYlJG8jD2m1N18yWMlUFs/GXYAIg1VwLZKa+oMAH354zPahojXKzMNpxyS POzQKuf7KNUJjSxrGo5G0E5NbDuMNQy2iSGllxZDdlJx1W3A7yTTfSLN2h8iK/80 ModfPbBjvca4xPeQAtLs/QLt/A1yp+4Mx/uyG0fMhGMrzuk7atF+9Ws9m+5vX2/k zv5wUX4W+eqzJGrVmAtL/HDYh+QvaxQssAtjrslkuZ/UwuvbkULF+HFv9flwrTqw 9oxrfysWwZUJPB67lCv2ZNTxjosWqSlYxtgjNVGHzdkFSc2kjarsL4DepN5bsdB6 KkSp0ICLxQjeh/kTP7GNpLC4vikeyTz9bTXRdmgZ3iIxkN5O/sqccAfCq2Zl9Amu 1VSajkKuTw1ySwsf386lckBu0U457LAoL5fj1VMCJItpUR7ARUu+riwhybn3yfAh RZrgIOAzw1RXMB+iBt9WfsGNHk+fOL8Jh9rbaLYSulo50aLdGrHlsj3CLCC/oLKh DdiWiIsQkM0= =EzyI -----END PGP SIGNATURE-----