-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 10 Jul 2020 17:37:54 +0530 Source: mailman Binary: mailman Architecture: source amd64 Version: 1:2.1.23-1+deb9u6 Distribution: stretch-security Urgency: high Maintainer: Mailman for Debian <pkg-mailman-hackers@lists.alioth.debian.org> Changed-By: Utkarsh Gupta <utkarsh@debian.org> Description: mailman - Powerful, web-based mailing list manager Changes: mailman (1:2.1.23-1+deb9u6) stretch-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix:CVE-2020-12108: Arbitrary Content Injection via the options login page. * Fix CVE-2020-15011: Arbitrary Content Injection via the private archive login page. Checksums-Sha1: ff92bd4b69ca5b3285d3f76b7e90c3c56da11d1a 2182 mailman_2.1.23-1+deb9u6.dsc bee329ca989fc4e217fc5cdb814a1a4ecde79615 9290881 mailman_2.1.23.orig.tar.gz 345149535b66bb7a5f6d1d4d6ab8439a837275b5 105480 mailman_2.1.23-1+deb9u6.debian.tar.xz e44a8a126483976c673649abe5ed3f3a3d0124c5 19240 mailman-dbgsym_2.1.23-1+deb9u6_amd64.deb 6143a832dec1c9a1a6319fdd282676fa87445a25 6838 mailman_2.1.23-1+deb9u6_amd64.buildinfo 9362ea76368c627100d68a42d12627ffc2ddfd82 4467564 mailman_2.1.23-1+deb9u6_amd64.deb Checksums-Sha256: 554c68c3c423bc7b9f0ba570a9b4485c8fd48f4eb2fb3c2645ae0c2448635d8d 2182 mailman_2.1.23-1+deb9u6.dsc b022ca6f8534621c9dbe50c983948688bc4623214773b580c2c78e4a7ae43e69 9290881 mailman_2.1.23.orig.tar.gz 0eb581d4890fa31d69de39dde694c0e4a39e4129817acb75ae542de31475bb31 105480 mailman_2.1.23-1+deb9u6.debian.tar.xz 3d5b51a390cfafd430366a7705626651200e504b9b7c6062486ea71ade02a4b6 19240 mailman-dbgsym_2.1.23-1+deb9u6_amd64.deb f9adfef64dc0e2ba1e221257d14caa54a5997894f3192ff673dda854857959fb 6838 mailman_2.1.23-1+deb9u6_amd64.buildinfo 54f75335942718843e46414aa4ca6bfb819baf2ee81c3938878859d824e6db4e 4467564 mailman_2.1.23-1+deb9u6_amd64.deb Files: ab514dc163dda4985c834f8f526bc8b0 2182 mail optional mailman_2.1.23-1+deb9u6.dsc ceb2d8427e29f4e69b2505423ffeb60b 9290881 mail optional mailman_2.1.23.orig.tar.gz 4733314c748f7c1155d80d2cf5eaaa3a 105480 mail optional mailman_2.1.23-1+deb9u6.debian.tar.xz 05d704a148dc7d61a0fab655de9a50f1 19240 debug extra mailman-dbgsym_2.1.23-1+deb9u6_amd64.deb 8813615d3a4fe77424510c984481616e 6838 mail optional mailman_2.1.23-1+deb9u6_amd64.buildinfo a9445ed3d2222cd4af7fa77151f3b408 4467564 mail optional mailman_2.1.23-1+deb9u6_amd64.deb -----BEGIN PGP SIGNATURE----- iQJHBAEBCAAxFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl8IYPYTHHV0a2Fyc2hA ZGViaWFuLm9yZwAKCRCCPpZ2BsNLlqerD/45CjhbgkX+Yb8ixWzt3wZ8IycNrFCn IQ8oCelzc/Tf9y+cVspGnYULX5zKyKExboxic2vOPZkT7dGAuMkojpQXYFJY2IJR BSnNOWHiWXFgTEG6N4r5IPuz0gyroWxIXjHrYuU2bXN4GEkgPtvO1XoF19o6q+lf /IHz5/svwvEZAZZDhs0sbrKbRKm6G/vc7Paduk6T7CideNK4qJcQMK3hawIG4iZ1 UJASv+/Ov4gMPbQgzBNKQCLKvKm9GJLMKDTw0Jp17GIR5wrFj+hzyZ1C799BFzg4 jsUmeKhU00u7phO2W6aCLwZCTMJnFcsRzoQEJwrpYkHk+irKBOX8l7bnhaaVzpy/ hnD9Xpqzw5bR1/2evSp47jbn+XENqUyURAEKCSxysTvZOVf4lDkrVK+EN5fB/rnF gUKlcfDjjaac15d03EU7IqKemdGSwXTve6D1zNZvHlegf5DALvT3ploUDXZpxm9l 0WcBSzlCwsS1FGif+cFOx3Xc4ELzNCkDCJ8igDufmm6HgBV5NMObRvLaKDp9aXYZ p2gb+ViWEQxXskqGgbf4GJxpVVOADkxYVYWaTiUlvuypr4ibWIIxCo0wtB3uooJN HOBgQE6bT4ObCX1dthQkFr4jcax1kCXb9UoXp9GnpdEz5sadkLf0UEnIgdPGYQsG DFiRT+V3dQo3QQ== =Zs5j -----END PGP SIGNATURE-----