[Mailman-Developers] opportunistically encrypted mailman lists with Autocrypt

2018-01-20 Thread holger krekel
Hi all, maybe some of you know me for my works on pypy, tox or pytest but this mail will be about something else ... In the last year i co-instigated a new opportunistic mail encryption effort called Autocrypt (https://autocrypt.org). With Autocrypt Level 1, mail clients (e.g. enigmail, K-9 mail

[Mailman-Developers] Mailman 2.1.26 Security release Feb 4, 2018

2018-01-20 Thread Mark Sapiro
An XSS vulnerability in the Mailman 2.1 web UI has been reported and assigned CVE-2018-5950 which is not yet public. I plan to release Mailman 2.1.26 along with a patch for older releases to fix this issue on Feb 4, 2018. At that time, full details of the vulnerability will be public. This is adv