Imminent release of a Mailman security fix.

19 Aug
2016
19 Aug
'16
2:09 a.m.
There is a CSRF vulnerability associated with the user options page. This could conceivably allow an attacker to obtain a user's password.
This is reported at https://bugs.launchpad.net/mailman/+bug/1614841.
I have developed a fix which is a small patch to two modules. I plan to release Mailman 2.1.23 with this and other fixes on Saturday, Aug 27 and also to post at the same time the patch which can be applied stand-alone.
Neither the bug report nor the fix reveals much detail about the attack, but to allay any concern, I'm delaying the release for a week to allow people to plan for installation of at least the patch at the time of release.
--
Mark Sapiro mark@msapiro.net The highway is for gamblers,
San Francisco Bay Area, California better use your sense - B. Dylan
2599
Age (days ago)
2599
Last active (days ago)
0 comments
1 participants
participants (1)
-
Mark Sapiro