-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 22 Oct 2021 14:32:39 +0200 Source: mailman Architecture: source Version: 1:2.1.29-1+deb10u2 Distribution: buster-security Urgency: high Maintainer: Mailman for Debian <pkg-mailman-hackers@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Changes: mailman (1:2.1.29-1+deb10u2) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * Fixed options login content injection vulnerability (CVE-2020-12108) * Fixed content injection vulnerability via the private login page (CVE-2020-15011) * Fix remote privilege escalation (CVE-2021-42096, CVE-2021-42097) Checksums-Sha1: 35f1e5c56dd5c51c07867b2983f511ecd81de55c 2238 mailman_2.1.29-1+deb10u2.dsc edbe1ad3973dc0a184792d6e633367fed95f8f41 101844 mailman_2.1.29-1+deb10u2.debian.tar.xz Checksums-Sha256: f1811b03f8c28eaa9230aa8b8d306d8dbd5e0520e00d962de80f76bc1473ee2f 2238 mailman_2.1.29-1+deb10u2.dsc d42e4c77a94c7abccc2ee516b6ce20c95348fc3a9d43eed17cf4f5ee5b9e916a 101844 mailman_2.1.29-1+deb10u2.debian.tar.xz Files: 4c98e6a5e2b0f3694c9d18c6878ea2bc 2238 mail optional mailman_2.1.29-1+deb10u2.dsc 730753009429ffecc0ec6356da3746b8 101844 mail optional mailman_2.1.29-1+deb10u2.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmFysxxfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EHBQQAJjwMMf+bfrbsK7ryENWT4QahpcGKyf8 a7UIQc7QJ/0crQPiDBRmb8iYlW3riQj2T+Gyi6nenUswkQw/+caziu/r6xeNBer9 Td9bQb6+jMmTtAnmJLlZNj4XsOTjd40DycV0GNa9NsiS+gkLL/sXJdQJvPMhFm/Y 1tsL+v0sYq4Wdm/EWeVPexLEOAGAjbuGRkYNoeHAZ4Ff5P0GTQrNg8/p4bCVe9GT o1Vqq0iyBKU4bg56t0BBXGN0h5CqJD2Uymv+YKAul1+xGa75HL02OyhvshXmghZE VHkRcJ9YDRIzWbIq2UQwbcI7X9sO5IQUFlSTkbVRvoyloX/5zmslRK2VZvOBNG8R dGt0DBEIRk+UPHJHGchoRHRAxHUWRj/qTspD3V75vDP4DFzb8X2xRVEqjwhWANxh 9L6tsu6UC+mSerusVn0pDezj2dewwC829qwFsgDqGZQ/+288ZkIcSz3fwMzOs1PW qAISj2S1dyYkUnPlx2NXVo2c/e9oJwneZIuZjz2XXgwXTVLTWwtAhhnUb1BAgNap en/WDWmQ6jY/MNz4zLnt/9TD3SDtDOg3HQDaGxexzkrUW1gS2vCTaBicXk4xNjQN pYXjBFKZryZcKRmRQltg3BbkkqNLgtSq415VYEVlIV+hTmn3j3NpSWLgY50P7Z4O E3Fqb+4LLwuh =BlN/ -----END PGP SIGNATURE-----