Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-14c006b8bb 2024-12-25 01:38:03.924476+00:00 -------------------------------------------------------------------------------- Name : sympa Product : Fedora 40 Version : 6.2.74 Release : 1.fc40 URL : http://www.sympa.org Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. -------------------------------------------------------------------------------- Update Information: Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 16 2024 Xavier Bachelot - 6.2.74-1 - Update to 6.2.74, fix for CVE-2024-55919 - Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-14c006b8bb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Sympa, a modern mailing list manager, allows privilege escalation through setuid wrappers. A local attacker can obtain root access. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2401-1
notes=Security fix for CVE-2020-12108. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-62f2df3ca4 2020-07-22 01:19:44.413051 --------------------------------------------------------------------------------Name : mailman Product : Fedora 31 Version : 2.1.34 Release : 1.fc31 URL : https://www.list.org/ Summary : Mailing list manager with built in Web access Description : Mailman is software to help manage email discussion lists, much like Majordomo and Smartmail. Unlike most similar products, Mailman gives each mailing list a webpage, and allows users to subscribe, unsubscribe, etc. over the Web. Even the list manager can administer his or her list entirely from the Web. Mailman also integrates most things people want to do with mailing lists, including archiving, mail news gateways, and so on. Documentation can be found in: /usr/share/doc/mailman When the package has finished installing, you will need to perform some additional installation steps, these are described in: /usr/share/doc/mailman/INSTALL.REDHAT --------------------------------------------------------------------------------Update Information: notes=Security fix for CVE-2020-12108 --------------------------------------------------------------------------------ChangeLog: * Fri Jul 3 2020 Pavel Zhukov - 3:2.1.34-1 - new version v2.1.34 * Mon May 11 2020 Pavel Zhukov - 3:2.1.33-1 - new version v2.1.33 * Wed May 6 2020 Pavel Zhukov - 3:2.1.32-2 - Change mode of /etc/mailman to 2755 (#1656765) * Wed May 6 2020 Pavel Zhukov - 3:2.1.32-1 - New version v2.1.32 --------------------------------------------------------------------------------References: [ 1 ] Bug #1848856 - CVE-2020-12108 mailman: /options/mailman allows Arbitrary Content Injection https://bugzilla.redhat.com/show_bug.cgi?id=1848856 --------------------------------------------------------------------------------This updatecan be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-62f2df3ca4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to sympa 6.2.54 : - Fixes CVE-2020-9369 - See https://www.sympa.community/security/2020-001.html for details. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-79516cb689 2020-03-12 21:55:08.821728 --------------------------------------------------------------------------------Name : sympa Product : Fedora 31 Version : 6.2.54 Release : 1.fc31 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to sympa 6.2.54 : - Fixes CVE-2020-9369 - See https://www.sympa.community/security/2020-001.html for details --------------------------------------------------------------------------------ChangeLog: * Mon Mar 2 2020 Xavier Bachelot 6.2.54-1 - Update to 6.2.54. * Fri Jan 31 2020 Fedora Release Engineering - 6.2.52-2.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Sun Jan 19 2020 Xavier Bachelot 6.2.52-2 - Add upstream patches to fix 2 scenario failures. * Fri Dec 27 2019 Xavier Bachelot 6.2.52-1 - Update to 6.2.52. * Sun Dec 22 2019 Xavier Bachelot 6.2.50-1 - Update to 6.2.50. - Re-enable Crypt::OpenSSL::X509 for EL8. * Fri Nov 29 2019 Xavier Bachelot 6.2.48-3 - Add patch to fix compile executables test on F32. - Add dependency on Socket6 and IO::Socket::IP (or alternatively Socket6 and IO::Socket::INET6 on EL6). - Add patch to fixldap 2 level query. - Re-enable Crypt::SMIME for EL8. - Re-enable all web subpackages for EL8. * Wed Oct 16 2019 Xavier Bachelot 6.2.48-2 - Don't require optional perl modules unavailable on EL8. - Disable httpd and lighttpd support for EL8 until missing bits are available. - Change sympa localstatedir owner/group to sympa:sympa. Fixes RHBZ#1761455. * Mon Sep 30 2019 Xavier Bachelot 6.2.48-1 - Update to 6.2.48. * Mon Sep 23 2019 Xavier Bachelot 6.2.46-1 - Update to 6.2.46. - Unbundle foundation-icons font. - Add dependency on LWP::Protocol::https (RHBZ#1753111). - Don't unbundle js-respond on EL8 (yet). --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-79516cb689' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to version 2.1.20.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-5333 2015-04-02 00:27:50 -------------------------------------------------------------------------------- Name : mailman Product : Fedora 22 Version : 2.1.20 Release : 1.fc22 URL : https://www.list.org/ Summary : Mailing list manager with built in Web access Description : Mailman is software to help manage email discussion lists, much like Majordomo and Smartmail. Unlike most similar products, Mailman gives each mailing list a webpage, and allows users to subscribe, unsubscribe, etc. over the Web. Even the list manager can administer his or her list entirely from the Web. Mailman also integrates most things people want to do with mailing lists, including archiving, mail news gateways, and so on. Documentation can be found in: /usr/share/doc/mailman When the package has finished installing, you will need to perform some additional installation steps, these are described in: /usr/share/doc/mailman/INSTALL.REDHAT -------------------------------------------------------------------------------- Update Information: Update to version 2.1.20. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1208059 - CVE-2015-2775 mailman: directory traversal in MTA transports that deliver programmatically https://bugzilla.redhat.com/show_bug.cgi?id=1208059 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mailman' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Several vulnerabilities have been discovered in Sympa, a mailing list manager, that allow to skip the scenario-based authorization mechanisms. This vulnerability allows to display the archives management page, and download and delete the list archives by . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2477-1
Janusz Niewiadomski and Wojciech Purczynski reported a buffer overflowin the address_match of listar (a listserv style mailing-list manager).. ------------------------------------------------------------------------ Debian Security Advisory DSA-123-1
Get the latest Linux and open source security news straight to your inbox.