Activity log for bug #1886117

Date Who What changed Old value New value Message
2020-07-03 00:39:07 Mark Sapiro bug added bug
2020-07-03 00:41:09 Mark Sapiro cve linked 2020-12137
2020-07-03 01:11:19 Mark Sapiro description This was fixed in Mailman 2.1.30 by using .bin for the extension, but a bug report was never created. The issue prior to 2.1.30 was a scrubbed attachment with no extion in it's name would be saved with a .obj extension and some web servers and or browsers would not recognize the .obj extension and possibly serve evil javascript as html. For more info see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12137 This was fixed in Mailman 2.1.30 by using .bin for the extension, but a bug report was never created. The issue prior to 2.1.30 was a scrubbed attachment with no extension in it's name would be saved with a .obj extension and some web servers and or browsers would not recognize the .obj extension and possibly serve evil javascript as html. For more info see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12137