Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for rubygem-rails-html-sanitizer ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2885-1 Rating: moderate References: #1201183 Cross-References: CVE-2022-32209 CVSS scores: CVE-2022-32209 (NVD) : 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2022-32209 (SUSE): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud Crowbar 9 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for rubygem-rails-html-sanitizer fixes the following issues: - CVE-2022-32209: Fixed a potential content injection under specific configurations (bsc#1201183). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-2885=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2022-2885=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): ruby2.1-rubygem-rails-html-sanitizer-1.0.3-8.11.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): ruby2.1-rubygem-rails-html-sanitizer-1.0.3-8.11.1 References: https://www.suse.com/security/cve/CVE-2022-32209.html https://bugzilla.suse.com/1201183 . SUSE Security Announcement: Addresses vulnerability in rubygem-rails-html-sanitizer affecting SUSE OpenStack Cloud Crowbar.. SUSE OpenStack Updates,rubygem-rails-html-sanitizer,Content Injection,SUSE Security Fixes. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for rubygem-rails-html-sanitizer ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2870-1 Rating: moderate References: #1201183 Cross-References: CVE-2022-32209 CVSS scores: CVE-2022-32209 (NVD) : 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2022-32209 (SUSE): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: SUSE Linux Enterprise High Availability 15 SUSE Linux Enterprise High Availability 15-SP1 SUSE Linux Enterprise High Availability 15-SP2 SUSE Linux Enterprise High Availability 15-SP3 SUSE Linux Enterprise High Availability 15-SP4 SUSE Linux Enterprise High Performance Computing 15 SUSE Linux Enterprise High Performance Computing 15-SP1 SUSE Linux Enterprise High Performance Computing 15-SP2 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Server 15 SUSE Linux Enterprise Server 15-SP1 SUSE Linux Enterprise Server 15-SP2 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15 SUSE Linux Enterprise Server for SAP Applications 15-SP1 SUSE Linux Enterprise Server for SAP Applications 15-SP2 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Storage 6 SUSE Linux Enterprise Storage 7 SUSE Linux Enterprise Storage 7.1 SUSE Manager Proxy 4.0 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.0 SUSE Manager Retail Branch Server 4.1 SUSE Manager Retail Branch Server 4.2 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.0 SUSE Manager Server 4.1 SUSE Manager Server 4.2 SUSE Manager Server 4.3 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for rubygem-rails-html-sanitizer fixes the following issues: - CVE-2022-32209: Fixed a potential content injection under specific configurations (bsc#1201183). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-2870=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-2870=1 - SUSE Linux Enterprise High Availability 15-SP4: zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2022-2870=1 - SUSE Linux Enterprise High Availability 15-SP3: zypper in -t patch SUSE-SLE-Product-HA-15-SP3-2022-2870=1 - SUSE Linux Enterprise High Availability 15-SP2: zypper in -t patch SUSE-SLE-Product-HA-15-SP2-2022-2870=1 - SUSE Linux Enterprise High Availability 15-SP1: zypper in -t patch SUSE-SLE-Product-HA-15-SP1-2022-2870=1 - SUSE Linux Enterprise High Availability 15: zypper in -t patch SUSE-SLE-Product-HA-15-2022-2870=1 Package List: - openSUSE Leap15.4 (aarch64 ppc64le s390x x86_64): ruby2.5-rubygem-rails-html-sanitizer-1.0.4-150000.4.3.1 ruby2.5-rubygem-rails-html-sanitizer-doc-1.0.4-150000.4.3.1 ruby2.5-rubygem-rails-html-sanitizer-testsuite-1.0.4-150000.4.3.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): ruby2.5-rubygem-rails-html-sanitizer-1.0.4-150000.4.3.1 ruby2.5-rubygem-rails-html-sanitizer-doc-1.0.4-150000.4.3.1 ruby2.5-rubygem-rails-html-sanitizer-testsuite-1.0.4-150000.4.3.1 - SUSE Linux Enterprise High Availability 15-SP4 (aarch64 ppc64le s390x x86_64): ruby2.5-rubygem-rails-html-sanitizer-1.0.4-150000.4.3.1 - SUSE Linux Enterprise High Availability 15-SP3 (aarch64 ppc64le s390x x86_64): ruby2.5-rubygem-rails-html-sanitizer-1.0.4-150000.4.3.1 - SUSE Linux Enterprise High Availability 15-SP2 (aarch64 ppc64le s390x x86_64): ruby2.5-rubygem-rails-html-sanitizer-1.0.4-150000.4.3.1 - SUSE Linux Enterprise High Availability 15-SP1 (aarch64 ppc64le s390x x86_64): ruby2.5-rubygem-rails-html-sanitizer-1.0.4-150000.4.3.1 - SUSE Linux Enterprise High Availability 15 (aarch64 ppc64le s390x x86_64): ruby2.5-rubygem-rails-html-sanitizer-1.0.4-150000.4.3.1 References: https://www.suse.com/security/cve/CVE-2022-32209.html https://bugzilla.suse.com/1201183 . The latest rubygem-rails-html-sanitizer update addresses a critical content injection vulnerability. Discover the steps to implement this fix efficiently.. SUSE Security Update,rubygem-rails-html-sanitizer,patch instructions,content injection,security fix. . LinuxSecurity.com Team
Several security issues were fixed in Mailman.. =========================================================================Ubuntu Security Notice USN-5121-2 November 01, 2021 mailman vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Mailman. Software Description: - mailman: Web-based mailing list manager Details: USN-5009-1 fixed vulnerabilities in Mailman. This update provides the corresponding updates for Ubuntu 20.04 LTS. In addition, the following CVEs were fixed: It was discovered that Mailman allows arbitrary content injection. An attacker could use this to inject malicious content. (CVE-2020-12108, CVE-2020-15011) It was discovered that Mailman improperly sanitize the MIME content. An attacker could obtain sensitive information by sending a special type of attachment. (CVE-2020-12137) Original advisory details: Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman did not properly associate cross-site request forgery (CSRF) tokens to specific accounts. A remote attacker could use this to perform a CSRF attack to gain access to another account. (CVE-2021-42097) Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman’s cross-site request forgery (CSRF) tokens for the options page are derived from the admin password. A remote attacker could possibly use this to assist in performing a brute force attack against the admin password. (CVE-2021-42096) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: mailman 1:2.1.29-1ubuntu3.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5121-2 https://ubuntu.com/security/notices/USN-5121-1 CVE-2020-12108,CVE-2020-12137, CVE-2020-15011, CVE-2021-42096, CVE-2021-42097 Package Information: https://launchpad.net/ubuntu/+source/mailman/1:2.1.29-1ubuntu3.1 . Mailman security issues addressed in Ubuntu 20.04 LTS. The patches resolve problems related to content manipulation and CSRF vulnerabilities.. Mailman Security Issues, Ubuntu Software Update, Mailman CSRF Fix, Ubuntu Mailing List Security. . Severity: Critical. LinuxSecurity.com Team
Several vulnerabilities were discovered in mailman, a web-based mailing list manager, which could result in arbitrary content injection via the options and private archive login pages, and CSRF attacks or privilege escalation via the user options page. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4991-1
An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: mailman:2.1 security update Advisory ID: RHSA-2021:1751-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:1751 Issue date: 2021-05-18 CVE Names: CVE-2020-12108 CVE-2020-15011 ==================================================================== 1. Summary: An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: Mailman is a program used to help manage e-mail discussion lists. Security Fix(es): * mailman: arbitrary content injection via the options login page (CVE-2020-12108) * mailman: arbitrary content injection via the private archive login page (CVE-2020-15011) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.4 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugsfixed (https://bugzilla.redhat.com/): 1848856 - CVE-2020-12108 mailman: arbitrary content injection via the options login page 1850684 - CVE-2020-15011 mailman: arbitrary content injection via the private archive login page 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: mailman-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.src.rpm aarch64: mailman-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.aarch64.rpm mailman-debuginfo-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.aarch64.rpm mailman-debugsource-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.aarch64.rpm ppc64le: mailman-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.ppc64le.rpm mailman-debuginfo-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.ppc64le.rpm mailman-debugsource-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.ppc64le.rpm s390x: mailman-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.s390x.rpm mailman-debuginfo-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.s390x.rpm mailman-debugsource-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.s390x.rpm x86_64: mailman-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.x86_64.rpm mailman-debuginfo-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.x86_64.rpm mailman-debugsource-2.1.29-11.module+el8.4.0+8277+5e2c6e6e.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-12108 https://access.redhat.com/security/cve/CVE-2020-15011 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.4_release_notes/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIUAwUBYKPvd9zjgjWX9erEAQi/FA/4imKLNgjJzeha/+e3lmddkF8jFNe20jc0 yfbCkPTwKi9zXFKbxRsdYGOxWiHxDOU+560qpHrs7H1ej6HjHSJfynLVfBS3G7wg 67po0BEIJRClsdzjTGNuK33Y0OeNJlJEBZqeGOEUPXBEZSWNJhnS/I7Ir9utWun2 s/AqZcyQOsn+Of9n6M6P9a+wwFS/wUi/+QZOImCzWd/K9WKK6JZ1UkcPipTe/9+b U2G1aE46LiB57GLWA108qwbwAv4O4btl1FAevkg+2+Wm2TgzOoDtLl2ath3ObQNJ mlCqW2IrWe/nsyvtXzb/tB3ODH0Hd8eZQ8xBiSG/qe2Hp9BUsjBtzoypmKthKqjb 6KDjhvoC52b6bGAjwjF6EtiLVq9c3a8MmHOj7RVVjWKizg47Ar/UbrC7Mjt2yPKu c7VFHeVt5UoxNFmuLbj5QZhrw7dYCnUoHU8e9Hdz/0VZVbT4rkoIbxED0fIKMcKr hGzqWccHwCQfMPjpE9c9Sdo4+sDTgvmqi0wcieett7m/SCZXy1mOES1Pmwo8le9V 7JefF7yVB6qvA0C/IJ72S6aEYSOuDbJUyumjrpf0SgBaQj6k51SixxY1Zg0WCx08 UJ0mpuwMeDtBYSYg4gdMojclCD3QSfTRdYikCwKKevTlXNy7eeuDc+1vVP0y7OkW VLPL2gvjNQ==8VFP -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Shibboleth could be made to display malicious content.. =========================================================================Ubuntu Security Notice USN-4925-1 April 22, 2021 shibboleth-sp vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Shibboleth could be made to display malicious content. Software Description: - shibboleth-sp: Federated web single sign-on system Details: Toni Huttunen and Fraktal Oy discovered that the Shibboleth Service provider allowed content injection due to allowing attacker-controlled parameters in error or other status pages. An attacker could use this to inject malicious content. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libapache2-mod-shib 3.0.4+dfsg1-1ubuntu0.1 libshibsp-plugins 3.0.4+dfsg1-1ubuntu0.1 libshibsp8 3.0.4+dfsg1-1ubuntu0.1 shibboleth-sp-common 3.0.4+dfsg1-1ubuntu0.1 shibboleth-sp-utils 3.0.4+dfsg1-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4925-1 CVE-2021-28963 Package Information: https://launchpad.net/ubuntu/+source/shibboleth-sp/3.0.4+dfsg1-1ubuntu0.1 . Uncover the Shibboleth flaw affecting Ubuntu 20.04 LTS and learn strategies to minimize content injection threats efficiently.. shibboleth threat, Ubuntu security notice, content injection risk. . LinuxSecurity.com Team
An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Recommended update for mailman ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1752-1 Rating: moderate References: #1171363 #1173369 Cross-References: CVE-2020-12108 CVE-2020-12137 CVE-2020-15011 Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for mailman to version 2.1.34 fixes the following issues: - The fix for lp#1859104 can result in ValueError being thrown on attempts to subscribe to a list. This is fixed and extended to apply REFUSE_SECOND_PENDING to unsubscription as well. (lp#1878458) - DMARC mitigation no longer misses if the domain name returned by DNS contains upper case. (lp#1881035) - A new WARN_MEMBER_OF_SUBSCRIBE setting can be set to No to prevent mailbombing of a member of a list with private rosters by repeated subscribe attempts. (lp#1883017) - Very long filenames for scrubbed attachments are now truncated. (lp#1884456) - A content injection vulnerability via the private login page has been fixed. CVE-2020-15011 (lp#1877379, bsc#1173369) - A content injection vulnerability via the options login page has been discovered and reported by Vishal Singh. CVE-2020-12108 (lp#1873722, bsc#1171363) - Bounce recognition for a non-compliant Yahoo format is added. - Archiving workaround for non-ascii in string.lowercase in some Python packages is added. - Thanks to Jim Popovitch, there is now a dmarc_moderation_addresses list setting that can be used to apply dmarc_moderation_action to mail From: addresses listed or matching listed regexps. This can be used to modify mail to addresses thatdon't accept external mail From: themselves. - There is a new MAX_LISTNAME_LENGTH setting. The fix for lp#1780874 obtains a list of the names of all the all the lists in the installation in order to determine the maximum length of a legitimate list name. It does this on every web access and on sites with a very large number of lists, this can have performance implications. See the description in Defaults.py for more information. - Thanks to Ralf Jung there is now the ability to add text based captchas (aka textchas) to the listinfo subscribe form. See the documentation for the new CAPTCHA setting in Defaults.py for how to enable this. Also note that if you have custom listinfo.html templates, you will have to add a tag to those templates to make this work. This feature can be used in combination with or instead of the Google reCAPTCHA feature added in 2.1.26. - Thanks to Ralf Hildebrandt the web admin Membership Management section now has a feature to sync the list's membership with a list of email addresses as with the bin/sync_members command. - There is a new drop_cc list attribute set from DEFAULT_DROP_CC. This controls the dropping of addresses from the Cc: header in delivered messages by the duplicate avoidance process. (lp#1845751) - There is a new REFUSE_SECOND_PENDING mm_cfg.py setting that will cause a second request to subscribe to a list when there is already a pending confirmation for that user. This can be set to Yes to prevent mailbombing of a third party by repeatedly posting the subscribe form. (lp#1859104) - Fixed the confirm CGI to catch a rare TypeError on simultaneous confirmations of the same token. (lp#1785854) - Scrubbed application/octet-stream MIME parts will now be given a .bin extension instead of .obj. CVE-2020-12137 (lp#1886117) - Added bounce recognition for a non-compliant opensmtpd DSN with Action: error.(lp#1805137) - Corrected and augmented some security log messages. (lp#1810098) - Implemented use of QRUNNER_SLEEP_TIME for bin/qrunner --runner=All. (lp#1818205) - Leading/trailing spaces in provided email addresses for login to private archives and the user options page are now ignored. (lp#1818872) - Fixed the spelling of the --no-restart option for mailmanctl. - Fixed an issue where certain combinations of charset and invalid characters in a list's description could produce a List-ID header without angle brackets. (lp#1831321) - With the Postfix MTA and virtual domains, mappings for the site list -bounces and -request addresses in each virtual domain are now added to data/virtual-mailman (-owner was done in 2.1.24). (lp#1831777) - The paths.py module now extends sys.path with the result of site.getsitepackages() if available. (lp#1838866) - A bug causing a UnicodeDecodeError in preparing to send the confirmation request message to a new subscriber has been fixed. (lp#1851442) - The SimpleMatch heuristic bounce recognizer has been improved to not return most invalid email addresses. (lp#1859011) This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2020-1752=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): mailman-2.1.34-bp152.7.3.1 References: https://www.suse.com/security/cve/CVE-2020-12108.html https://www.suse.com/security/cve/CVE-2020-12137.html https://www.suse.com/security/cve/CVE-2020-15011.html https://bugzilla.suse.com/1171363 https://bugzilla.suse.com/1173369 -- . openSUSE Security Update: Recommended update for mailman___________________________________________. update, fixes, three, vulnerabilities, opensuse, security, recommended. . LinuxSecurity.com Team
An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Recommended update for mailman ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1707-1 Rating: moderate References: #1171363 #1173369 Cross-References: CVE-2020-12108 CVE-2020-12137 CVE-2020-15011 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for mailman to version 2.1.34 fixes the following issues: - The fix for lp#1859104 can result in ValueError being thrown on attempts to subscribe to a list. This is fixed and extended to apply REFUSE_SECOND_PENDING to unsubscription as well. (lp#1878458) - DMARC mitigation no longer misses if the domain name returned by DNS contains upper case. (lp#1881035) - A new WARN_MEMBER_OF_SUBSCRIBE setting can be set to No to prevent mailbombing of a member of a list with private rosters by repeated subscribe attempts. (lp#1883017) - Very long filenames for scrubbed attachments are now truncated. (lp#1884456) - A content injection vulnerability via the private login page has been fixed. CVE-2020-15011 (lp#1877379, bsc#1173369) - A content injection vulnerability via the options login page has been discovered and reported by Vishal Singh. CVE-2020-12108 (lp#1873722, bsc#1171363) - Bounce recognition for a non-compliant Yahoo format is added. - Archiving workaround for non-ascii in string.lowercase in some Python packages is added. - Thanks to Jim Popovitch, there is now a dmarc_moderation_addresses list setting that can be used to apply dmarc_moderation_action to mail From: addresses listed or matching listed regexps. This can be used to modify mail to addresses that don'taccept external mail From: themselves. - There is a new MAX_LISTNAME_LENGTH setting. The fix for lp#1780874 obtains a list of the names of all the all the lists in the installation in order to determine the maximum length of a legitimate list name. It does this on every web access and on sites with a very large number of lists, this can have performance implications. See the description in Defaults.py for more information. - Thanks to Ralf Jung there is now the ability to add text based captchas (aka textchas) to the listinfo subscribe form. See the documentation for the new CAPTCHA setting in Defaults.py for how to enable this. Also note that if you have custom listinfo.html templates, you will have to add a tag to those templates to make this work. This feature can be used in combination with or instead of the Google reCAPTCHA feature added in 2.1.26. - Thanks to Ralf Hildebrandt the web admin Membership Management section now has a feature to sync the list's membership with a list of email addresses as with the bin/sync_members command. - There is a new drop_cc list attribute set from DEFAULT_DROP_CC. This controls the dropping of addresses from the Cc: header in delivered messages by the duplicate avoidance process. (lp#1845751) - There is a new REFUSE_SECOND_PENDING mm_cfg.py setting that will cause a second request to subscribe to a list when there is already a pending confirmation for that user. This can be set to Yes to prevent mailbombing of a third party by repeatedly posting the subscribe form. (lp#1859104) - Fixed the confirm CGI to catch a rare TypeError on simultaneous confirmations of the same token. (lp#1785854) - Scrubbed application/octet-stream MIME parts will now be given a .bin extension instead of .obj. CVE-2020-12137 (lp#1886117) - Added bounce recognition for a non-compliant opensmtpd DSN with Action: error. (lp#1805137) - Corrected and augmented some security log messages. (lp#1810098) - Implemented use of QRUNNER_SLEEP_TIME for bin/qrunner --runner=All. (lp#1818205) - Leading/trailing spaces in provided email addresses for login to private archives and the user options page are now ignored. (lp#1818872) - Fixed the spelling of the --no-restart option for mailmanctl. - Fixed an issue where certain combinations of charset and invalid characters in a list's description could produce a List-ID header without angle brackets. (lp#1831321) - With the Postfix MTA and virtual domains, mappings for the site list -bounces and -request addresses in each virtual domain are now added to data/virtual-mailman (-owner was done in 2.1.24). (lp#1831777) - The paths.py module now extends sys.path with the result of site.getsitepackages() if available. (lp#1838866) - A bug causing a UnicodeDecodeError in preparing to send the confirmation request message to a new subscriber has been fixed. (lp#1851442) - The SimpleMatch heuristic bounce recognizer has been improved to not return most invalid email addresses. (lp#1859011) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1707=1 Package List: - openSUSE Leap 15.2 (x86_64): mailman-2.1.34-lp152.7.3.1 mailman-debuginfo-2.1.34-lp152.7.3.1 mailman-debugsource-2.1.34-lp152.7.3.1 References: https://www.suse.com/security/cve/CVE-2020-12108.html https://www.suse.com/security/cve/CVE-2020-12137.html https://www.suse.com/security/cve/CVE-2020-15011.html https://bugzilla.suse.com/1171363 https://bugzilla.suse.com/1173369 -- . Addresses multiple security issues in openSUSE mailman, boosting protection and usability with added featuresand enhancements.. mailman Update, openSUSE vulnerabilities, mailman security, recommended patch, email list management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.