-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 06 Apr 2015 18:17:34 +0200 Source: mailman Binary: mailman Architecture: source amd64 Version: 1:2.1.15-1+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Mailman for Debian <pkg-mailman-hackers@lists.alioth.debian.org> Changed-By: Thijs Kinkhorst <thijs@debian.org> Description: mailman - Powerful, web-based mailing list manager Closes: 781626 Changes: mailman (1:2.1.15-1+deb7u1) wheezy-security; urgency=high . * Fix security issue: path traversal through local_part. Affects installations which use an Exim or Postfix transport instead of fixed aliases; attacker needs to be able to place files on the local filesystem. (CVE-2015-2775, Closes: 781626) Checksums-Sha1: aee14030d2520c20a86296801bd6354080b3dd20 1699 mailman_2.1.15-1+deb7u1.dsc 462ac96331491c76aca0128d8f9ced18c50a75d7 8468107 mailman_2.1.15.orig.tar.gz fc82154bac4573c6e0d64ad85bbf82969c2f2024 99583 mailman_2.1.15-1+deb7u1.debian.tar.gz 6f15299e7c0a075ce6ebd6e8c484f6d13d4e21fc 10153246 mailman_2.1.15-1+deb7u1_amd64.deb Checksums-Sha256: 4e4f460bf88ab0bee805ba841ee8ad7ca6c5dbda6b336d03d7b157ece8c301c2 1699 mailman_2.1.15-1+deb7u1.dsc f355fb3d31772b488449e6f5173dafd31edca93172c307244c791d25d9e2bec8 8468107 mailman_2.1.15.orig.tar.gz 1bd1b8227d0642de2a63106451c8ce81f5499ed165c3b2a1b9c4be8334512218 99583 mailman_2.1.15-1+deb7u1.debian.tar.gz c8317fc177ceb2723cbb5ec8c76c4852b2c06f9ba39a83b7174f71568f10e284 10153246 mailman_2.1.15-1+deb7u1_amd64.deb Files: d865f6501606c842008afe395801defa 1699 mail optional mailman_2.1.15-1+deb7u1.dsc 7d207489e8e9de0727cb334d46029833 8468107 mail optional mailman_2.1.15.orig.tar.gz a67a347f2c8b023fa7ad4fa6b6f4ff5b 99583 mail optional mailman_2.1.15-1+deb7u1.debian.tar.gz bab8e5b6b8c12a35bb3532178925218d 10153246 mail optional mailman_2.1.15-1+deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQEcBAEBCAAGBQJVIrJxAAoJEFb2GnlAHawE7aMH+wfUeW7YntBJ9zbPqQsc7yRC AZ1+DV9dO2tcI0/cXajrWuY37F7aHYb7PXCCsesvZRcY7StmP7f6puncuAy/QXab GsU0V0go0ZuR7Eh+QdNcivd+Yh1z0om2nTq5BqpqIfh2M7AqIOk+HsQrcb3c0qFm vukEITVzGN56D2dynyDjPTUfwoQehX6vL1sMjVQlGhjFOA8GSySXYLPBs6odduPR CminPU1EEXAPqS/pfCezOVfRHBWM4oWBzGwBfmsKvxqxsoDHDatF2Xry+wiZJsFU 7qeA3b+ktiWN6HoeF5F+7W4vQALCQoqqxqyfvNSCt+KvKmX5b7ELsx915ZMaVsQ= =pxo1 -----END PGP SIGNATURE-----