<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>129136</bug_id>
          
          <creation_ts>2006-04-07 07:42 0000</creation_ts>
          <short_desc>net-mail/mailman XSS issues</short_desc>
          <delta_ts>2006-05-01 11:49:56 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://mail.python.org/pipermail/mailman-announce/2006-April/000084.html</bug_file_loc>
          <status_whiteboard>B4 [noglsa] DerCorny</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>bughunter@jankoh.dyndns.org</cc>
    
    <cc>hanno@gentoo.org</cc>
    
    <cc>net-mail@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-04-07 07:42:17 0000</bug_when>
            <thetext>Mailman 2.1.8rc1 was released for the final test of 2.1.8.

Important: This is not only a release candidate but also include a fix 
for a cross-site scripting bug found in 2.1.7.  All sites running 
previous versions are adviced to upgrade to 2.1.8(rc1).  I am going to 
release the final by the next weekend if nothing serious happens.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-04-07 10:43:59 0000</bug_when>
            <thetext>net-mail, please provide fixed ebuilds, thank you. Do you want to wait for stable (B4 has a target  delay of 20days, btw)?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>langthang@gentoo.org</who>
            <bug_when>2006-04-12 15:26:50 0000</bug_when>
            <thetext>net-mail team is not interested in maintain this package. It has a list of open bugs ( http://tinyurl.com/fhhet ) and we don&apos;t have enough man power to test it with every MTAs that mailman supports. Please find a new maintainer or package.mask --&gt; remove it from the tree.

Best regards,
Tuan V.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-04-12 22:57:22 0000</bug_when>
            <thetext>core mailed about new maintainer.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mholzer@gentoo.org</who>
            <bug_when>2006-04-14 09:29:46 0000</bug_when>
            <thetext>*** Bug 124624 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mholzer@gentoo.org</who>
            <bug_when>2006-04-14 09:51:17 0000</bug_when>
            <thetext>ebuild in cvs</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-04-15 00:40:49 0000</bug_when>
            <thetext>mholzer/hanno please update maintainer information in metadata.xml

Arches please test and mark mailman-2.1.8_rc1 stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2006-04-15 08:18:12 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2006-04-15 17:16:00 0000</bug_when>
            <thetext>Stable on SPARCenstein</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>halcy0n@gentoo.org</who>
            <bug_when>2006-04-16 20:58:08 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2006-04-28 12:20:20 0000</bug_when>
            <thetext>amd64 is late</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>metalgod@gentoo.org</who>
            <bug_when>2006-04-29 09:21:47 0000</bug_when>
            <thetext>amd64 done!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-04-30 09:06:02 0000</bug_when>
            <thetext>This one is ready for GLSA decision. I tend to vote NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-04-30 15:36:02 0000</bug_when>
            <thetext>Voting no, too</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-05-01 01:57:55 0000</bug_when>
            <thetext>i tend to vote no</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2006-05-01 11:49:56 0000</bug_when>
            <thetext>Voting no and closing.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>