Your message dated Mon, 06 Apr 2015 16:06:28 +0000
with message-id <[email protected]>
and subject line Bug#781626: fixed in mailman 1:2.1.18-2
has caused the Debian Bug report #781626,
regarding mailman: CVE-2015-2775: Path traversal vulnerability
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
781626: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=781626
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: mailman
Version: 1:2.1.18-1
Severity: important
Tags: security patch upstream fixed-upstream
Hi,
the following vulnerability was published for mailman.
CVE-2015-2775[0]:
Path traversal vulnerability
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2015-2775
[1] https://bugs.launchpad.net/mailman/+bug/1437145
[2] https://mail.python.org/pipermail/mailman-announce/2015-March/000209.html
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: mailman
Source-Version: 1:2.1.18-2
We believe that the bug you reported is fixed in the latest version of
mailman, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thijs Kinkhorst <[email protected]> (supplier of updated mailman package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Mon, 06 Apr 2015 15:36:15 +0000
Source: mailman
Binary: mailman
Architecture: source amd64
Version: 1:2.1.18-2
Distribution: unstable
Urgency: high
Maintainer: Mailman for Debian <[email protected]>
Changed-By: Thijs Kinkhorst <[email protected]>
Description:
mailman - Powerful, web-based mailing list manager
Closes: 781626
Changes:
mailman (1:2.1.18-2) unstable; urgency=high
.
* Fix security issue: path traversal through local_part.
Affects installations which use an Exim or Postfix transport
instead of fixed aliases; attacker needs to be able to place
files on the local filesystem.
(CVE-2015-2775, Closes: 781626)
Checksums-Sha1:
6cf7e1c8564f4a7b5cbad45a31d0e668d82ef010 1697 mailman_2.1.18-2.dsc
224a12136519bf0b3c1c4b8de62d37cd1a9eee4a 103968 mailman_2.1.18-2.debian.tar.xz
f2bd682a476df319677d6f5471f8f7bb75fc0bda 4349946 mailman_2.1.18-2_amd64.deb
Checksums-Sha256:
141626fdcc78e574a4e916624d8bc909668973e0e751226bf049b0183acdfc2e 1697
mailman_2.1.18-2.dsc
f40bf863a71d44dd6900232b922fa65f5d48443d591dfe77260fbe50da04094a 103968
mailman_2.1.18-2.debian.tar.xz
a25b96f34b457ccd1f4943f8926ecffe76f8591bf511f9800c034d4cb163d429 4349946
mailman_2.1.18-2_amd64.deb
Files:
ad6dd3c21ec46a21a251fc75a1aa69de 1697 mail optional mailman_2.1.18-2.dsc
226a349c0304459d725db61175a708a8 103968 mail optional
mailman_2.1.18-2.debian.tar.xz
fb9dee73a62e64bfcf265509f617384b 4349946 mail optional
mailman_2.1.18-2_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQEcBAEBCAAGBQJVIqpwAAoJEFb2GnlAHawEB7AIAIqQM68u8EwoZqw0KtDN7Cr1
3IPfXEzMiRzmuxYTilT12jC6SDaBJCQdeaChgoN0Yt2N3WJnLTOjWdW/a6INjX21
wmbIDWmovWDyq10CX7R9W9VG6jX/+gRske0jQYL2keT4EAEHqG3FV0kijxbGXDj8
PXZ6p6wAaVRZkMPGWXCgOGqG9/EF93XBvlKw3T3mK0oGijlpi9yZo/Z6FjiYmcLO
iSDcqt0W9h1t1vGfksuu8g31sMBLLLHeb/B7ODneX6l1OTZD7vqVkZJ4rG00z9fd
QqX6HS13/AkVA+XxtMmflBFxeEOiJZVlCf6BNwi3BtjxEXwNcvduN5OIDTstfno=
=JUUL
-----END PGP SIGNATURE-----
--- End Message ---