This update for mailman to version 2.1.27 fixes the following issues:
This security issue was fixed:
- CVE-2018-0618: Additional protections against injecting scripts into
listinfo and error messages pages (bsc#1099510).
These non-security issues were fixed:
- The hash generated when SUBSCRIBE_FORM_SECRET is set could have been the
same as one generated at the same time for a different list and IP
address.
- An option has been added to bin/add_members to issue invitations instead
of immediately adding members.
- A new BLOCK_SPAMHAUS_LISTED_IP_SUBSCRIBE setting has been added to
enable blocking web subscribes from IPv4 addresses listed in Spamhaus
SBL, CSS or XBL. It will work with IPv6 addresses if Python's
py2-ipaddress module is installed. The module can be installed via pip
if not included in your Python.
- Mailman has a new 'security' log and logs authentication failures to the
various web CGI functions. ...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2018-691=1
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-691=1
- openSUSE Leap 42.3 (x86_64):
mailman-2.1.27-2.6.1
mailman-debuginfo-2.1.27-2.6.1
mailman-debugsource-2.1.27-2.6.1
- openSUSE Leap 15.0 (x86_64):
mailman-2.1.27-lp150.2.3.1
mailman-debuginfo-2.1.27-lp150.2.3.1
mailman-debugsource-2.1.27-lp150.2.3.1
https://www.suse.com/security/cve/CVE-2018-0618.html
https://bugzilla.suse.com/show_bug.cgi?id=1099510
--
Get the latest Linux and open source security news straight to your inbox.