-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 23 Oct 2021 17:38:30 +0100 Source: mailman Binary: mailman Architecture: source amd64 Version: 1:2.1.23-1+deb9u7 Distribution: stretch-security Urgency: high Maintainer: Mailman for Debian <pkg-mailman-hackers@lists.alioth.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: mailman - Powerful, web-based mailing list manager Changes: mailman (1:2.1.23-1+deb9u7) stretch-security; urgency=high . * Non-maintainer upload by the LTS team. * CVE-2021-42096 & CVE-2021-42097: Fix a potential remote privilege escalation vulnerability. A CSRF token value was derived from the admin password, and could have been useful in conducting a brute-force attack against that password. Checksums-Sha1: 52be79135f097f19d1772f36d11a94ecd2729b2b 2153 mailman_2.1.23-1+deb9u7.dsc bee329ca989fc4e217fc5cdb814a1a4ecde79615 9290881 mailman_2.1.23.orig.tar.gz 5b6ecc3fc2492824f092a624d26e90caf767dac6 106912 mailman_2.1.23-1+deb9u7.debian.tar.xz 81335716de93ff3d9a70c49d47b169a9f416d175 19234 mailman-dbgsym_2.1.23-1+deb9u7_amd64.deb dbd1f4dfaf745e55860a4de27c1963292daa7371 6763 mailman_2.1.23-1+deb9u7_amd64.buildinfo 07aa105eb318e5ab02982c6aada305d044b1d7ba 4467570 mailman_2.1.23-1+deb9u7_amd64.deb Checksums-Sha256: f7919603bb9b6ba86521fc1a45b949c87372aea7de0dd86134e803447945546d 2153 mailman_2.1.23-1+deb9u7.dsc b022ca6f8534621c9dbe50c983948688bc4623214773b580c2c78e4a7ae43e69 9290881 mailman_2.1.23.orig.tar.gz bf04bce623e9f26162bd8a3ad42b246ceea7c9d780d5d9b37ec7f5139d2dca5e 106912 mailman_2.1.23-1+deb9u7.debian.tar.xz db07fed600f18d2e93b08b99df314d110f6f5d7e5015f71a6290c04c1c93844e 19234 mailman-dbgsym_2.1.23-1+deb9u7_amd64.deb fc25b6741e7a521c5ee870adca1044513eade8a318a6923839ac3fff5e6ff16b 6763 mailman_2.1.23-1+deb9u7_amd64.buildinfo 2c2dbab200c5aa255177ca8dd2f98ec62d60080515ffe9f7ccff378365c21047 4467570 mailman_2.1.23-1+deb9u7_amd64.deb Files: e6937d579a7194dccd8641c673c8dddf 2153 mail optional mailman_2.1.23-1+deb9u7.dsc ceb2d8427e29f4e69b2505423ffeb60b 9290881 mail optional mailman_2.1.23.orig.tar.gz ec983e9ca882bbceb464ddbd3d1c298b 106912 mail optional mailman_2.1.23-1+deb9u7.debian.tar.xz 3aaf5d71bbcff9a08c68fe36414c7c89 19234 debug extra mailman-dbgsym_2.1.23-1+deb9u7_amd64.deb 9e5acd82f008511be7ed823eff15c0ad 6763 mail optional mailman_2.1.23-1+deb9u7_amd64.buildinfo 7aa7846037ba8b8934eb3880d86accf1 4467570 mail optional mailman_2.1.23-1+deb9u7_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmF0PfwACgkQHpU+J9Qx Hliq8w//ZqmAlmHgeVUxxdUyX/Hd/ZjoFLDRo1Bt/52gavHUMW4nfJj8KzhPcaa9 wY90PR0mBbzJO2BtOJUGsn4TY/qNM88Kt6ssfn/ekLRMOZjvJQoy0GXwMJor4d7/ paOl5oqxiCAr75qpaGoxLw6VRo37YmgHX5eH2bkpLTLz0KMYvXVwhj2hjofBRZ0b baZn5lHNLvovQjT2iiovLyulRWTcwNT0kh3QATo2R3biPKBXcsVsbM2FJL7W8IZy 0eoAf9o8ls9VLVJ3gDwnkN27GXqA2Neni1b4pSjgKGI6dVdkYsVOH/2ZmOoIymuw nBn1L32xuApS9zsTtALxy19Gu3NqQ6bZ1UNSMvX4GQxIJL9zxznwTyaN+Yab1CBL 7CAr5HEdJ2Q2osML+CrCV+14Itw7Id6dpW0zBfprV3XszsKVbWKCFykv9vqtZcI5 lORnUKYyNZykLh/6DFHw4kumUcdQ7/Xtn1UVxtcBe81/qZO5gXXE6v4j+FRBARNw FbLp8YFD3DY6S5weoZu9MrFQ3NmhtH5XBVQGOIehF7gw8BWW8B4u6sNVy9thO7K4 lDQp+pJBcNw504huoIkuJy0hS6l2iYQZgiPjf/56iTfT46sYEDu1lxnkk+yGBQ1p K4alMe1gtfuGJnfE/eSr9OjIefTCTDiHKkGqY1V5GCcYuq89yX0= =6wDH -----END PGP SIGNATURE-----