-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 07 May 2020 12:37:42 +0100 Source: mailman Binary: mailman Architecture: source amd64 Version: 1:2.1.18-2+deb8u6 Distribution: jessie-security Urgency: high Maintainer: Mailman for Debian <pkg-mailman-hackers@lists.alioth.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: mailman - Powerful, web-based mailing list manager Changes: mailman (1:2.1.18-2+deb8u6) jessie-security; urgency=high . * CVE-2020-12108: Fix an arbitrary content injection vulnerability via the options login page. Checksums-Sha1: 29fd1e767f7062a07d9dc467b433b224676971be 2085 mailman_2.1.18-2+deb8u6.dsc 3ea3aff36984a7ccc92bc784b7e76cb8156fa4fc 9095038 mailman_2.1.18.orig.tar.gz 0538a7293974f60255be5e377ee7b20b4c14bbfe 108200 mailman_2.1.18-2+deb8u6.debian.tar.xz 194639178b826db61cebc4c59bf57fa11d011324 4305038 mailman_2.1.18-2+deb8u6_amd64.deb Checksums-Sha256: 27da9cb8e4d0b50e42a3b7fd90421a48e92d72945da498e5c141d2491e8d9e93 2085 mailman_2.1.18-2+deb8u6.dsc dc1d605321448e7e5e804e26493f7689a0b17f0810505dc3f9774f9519308349 9095038 mailman_2.1.18.orig.tar.gz 088a1142a6fcb5659a12d0ec733066510b0cf8196e6cf5f391a3291f4ae20825 108200 mailman_2.1.18-2+deb8u6.debian.tar.xz 33a5797c13b798521b676564a10b096bd58696005fcf0c6a255865a168659820 4305038 mailman_2.1.18-2+deb8u6_amd64.deb Files: 498b2c87a0b6c3a1eada3fdd774ba30e 2085 mail optional mailman_2.1.18-2+deb8u6.dsc 02ce493711248e1d3723356188446d9f 9095038 mail optional mailman_2.1.18.orig.tar.gz 26538314582800b4d00daf1347db267f 108200 mail optional mailman_2.1.18-2+deb8u6.debian.tar.xz f2b72511f34bddb3e225da981ffddeb8 4305038 mail optional mailman_2.1.18-2+deb8u6_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl6z9QMACgkQHpU+J9Qx Hlj3ww/+I46ZVC9ivSxrIjFl/fV7gGJZCqEa3Jkai7rMg6YfbzVfjnVLDDVkAY/E wj2+2jCkOu+BQc/Wf/Kg+3W80ApVvu45ZE07rfS1O68zRUOFkw65Bs3/3rbNBt7T prayT3sFG6LP0Fdu9SV+QeEBH4aNel5xdVqoUCyzLZwrYIzrYaSTyDLQow+awTcI URhiWtLX+vj9sKBkeh3QUfSjl9txyRKdxpfiD8TDBtGoGoM8JbrVAfYYU4+8GYb8 NG1IohtQgZR0OpsnasGnM0uXpwMdKcWri3v8DAoObZCgeqIGn4FgTJhw295DOFPT fnHD6JoySvYTXQCdumddaZ7+sjcSdomsAMDn9ZE293LuXxUfoxus6BZLbbZRmrc8 qkRZ+3M1MyPXCTLy+1dHjq8Mm+Hn+Szowg3TGuoBXJKLo3JgeMUZpNqgysSz+55v eidHm8xSbXiHy4jDklu/MVZQMlwBCDGrhx4krHZLxtokv4CpZdMq8DL64AnRcF0v Jvz7Y/D3LN0geyeZu3AvtzMMRfa07i3x74W9mgTsTF1mFujWEnYBu6BFQ3cM1I8W Su0wNT6FePMMBJYj+5eXhBkAQapaeBeNgNW1mTafLAuKkHKrne6ZPV00Qxe+yYoY vwognopEsqZ34zESzDBSeyVDUaWRNph8je9gu9SGkdjj1hSbtwY= =vw4K -----END PGP SIGNATURE-----