Sync mailman 1:2.1.18-2 (main) from Debian unstable (main)

Bug #1454866 reported by Artur Rona
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mailman (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please sync mailman 1:2.1.18-2 (main) from Debian unstable (main)

Explanation of the Ubuntu delta and why it can be dropped:
  * SECURITY UPDATE: path traversal vulnerability
    - debian/patches/CVE-2015-2775.patch: validate list name in
      Mailman/Utils.py, add comment to Mailman/Defaults.py.in.
    - CVE-2015-2775
  * SECURITY UPDATE: path traversal vulnerability
    - debian/patches/CVE-2015-2775.patch: validate list name in
      Mailman/Utils.py, add comment to Mailman/Defaults.py.in.
    - CVE-2015-2775

CVE has been fixed in Debian, as well.

Changelog entries since current wily version 1:2.1.18-1ubuntu1:

mailman (1:2.1.18-2) unstable; urgency=high

  * Fix security issue: path traversal through local_part.
    Affects installations which use an Exim or Postfix transport
    instead of fixed aliases; attacker needs to be able to place
    files on the local filesystem.
    (CVE-2015-2775, Closes: 781626)

 -- Thijs Kinkhorst <email address hidden> Mon, 06 Apr 2015 15:36:15 +0000

CVE References

Artur Rona (ari-tczew)
Changed in mailman (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Daniel Holbach (dholbach) wrote :

This bug was fixed in the package mailman - 1:2.1.18-2
Sponsored for Artur Rona (ari-tczew)

---------------
mailman (1:2.1.18-2) unstable; urgency=high

  * Fix security issue: path traversal through local_part.
    Affects installations which use an Exim or Postfix transport
    instead of fixed aliases; attacker needs to be able to place
    files on the local filesystem.
    (CVE-2015-2775, Closes: 781626)

 -- Thijs Kinkhorst <email address hidden> Mon, 06 Apr 2015 15:36:15 +0000

Changed in mailman (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.