Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 208710
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Tobias Scherbaum <dertobi123@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
mailman-2.1.9-fix-XSS.patch mailman-2.1.9-fix-XSS.patch patch Jonathan Smith 2008-02-05 08:54 0000 11.02 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 208710 depends on: Show dependency tree
Bug 208710 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-02-03 09:50 0000
Quoting the announcement [1]:

"I am happy to announce the second beta release of Mailman 2.1.10. For
technical reasons, there was no 'b2' release.

This is a security and bug fix release and it is highly recommended
that all sites upgrade to this version.  Mailman 2.1.10 also adds support
for two new language translations, Hebrew and Slovak and a few new features.

[...]

~  Security

~    - The 2.1.9 fixes for CVE-2006-3636 have been enhanced.  In particular,
~      many potential cross-site scripting attacks have are now detected in
~      editing templates and updating the list's info attribute via the web
~      admin interface.  Thanks again to Moritz Naumann for assistance with
~      this."

Note that while speaking of 2.1.10b1 in the initial announcement the new
released version is 2.1.10b3 according to [2].

[1] http://mail.python.org/pipermail/mailman-announce/2008-February/000095.html
[2] http://mail.python.org/pipermail/mailman-announce/2008-February/000096.html

------- Comment #1 From Jonathan Smith 2008-02-05 08:52:17 0000 -------
CVE-2008-0564 has been allocated for these issues.

------- Comment #2 From Jonathan Smith 2008-02-05 08:54:00 0000 -------
Created an attachment (id=142699) [details]
mailman-2.1.9-fix-XSS.patch

Oh, also, if $MAINTAINER doesn't want to update to a beta release (I wouldn't),
I'm attaching a patch which was given to me by upstream to fix the issue.

------- Comment #3 From Hanno Boeck 2008-02-05 11:24:16 0000 -------
Added -r3. Archs, please go ahead.

Note that this introduces the "reworked" mailman-ebuild, which installs into
fhs-compliant locations and can be configured much better.

------- Comment #4 From Dawid Węgliński 2008-02-05 13:12:26 0000 -------
 * An example Mailman configuration file for Apache has been installed into:
 *   /50_mailman.conf

There's missing ${APACHE_MODULES_CONFDIR} variable (missing eclass?)

x86 stable

------- Comment #5 From Robert Buchholz 2008-02-05 13:14:38 0000 -------
Arches, please test and mark stable:
=net-mail/mailman-2.1.9-r3
Target keywords : "amd64 ppc release sparc x86"

------- Comment #6 From Robert Buchholz 2008-02-05 13:15:06 0000 -------
sorry, removing x86 again.

------- Comment #7 From Hanno Boeck 2008-02-06 11:48:26 0000 -------
amd64 done

------- Comment #8 From Raúl Porcel 2008-02-07 13:51:36 0000 -------
sparc stable

------- Comment #9 From Tobias Scherbaum 2008-02-07 18:30:44 0000 -------
ppc stable plus re-adding amd64.

------- Comment #10 From Hanno Boeck 2008-02-08 13:14:33 0000 -------
Seems I've stabilized amd64 in my local cvs tree without committing...

Now done. Security, please go ahead with glsa.

------- Comment #11 From Sune Kloppenborg Jeppesen 2008-02-10 14:50:39 0000 -------
This one is ready for GLSA vote. I tend to vote NO.

------- Comment #12 From Pierre-Yves Rofes 2008-02-10 15:36:44 0000 -------
voting NO, and I close even if we don't have 2 full NO votes since it's XSS.
feel free to reopen if you disagree.

------- Comment #13 From Hanno Boeck 2008-02-12 20:56:12 0000 -------
Erh? Yes, it's an XSS and thus it can be used to steal accounts, which is a
major issue. Why shouldn't this cause a GLSA??

Vote YES (if my opinion as the package maintainer counts) and volunteer to
write the glsa if neccessary.

------- Comment #14 From Robert Buchholz 2008-02-12 21:00:59 0000 -------
Is it a persistent or non-persistent XSS? Non-persistent issues usually do not
get GLSA'd.

------- Comment #15 From Peter Volkov 2008-02-23 18:15:11 0000 -------
Fixed in release snapshot.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug