Red Hat Bugzilla – Bug 56865
Security updates have been released by the authors
Last modified: 2008-05-01 11:38:01 EDT
From Bugzilla Helper:
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312461)
Description of problem:
This clip was recently posted by the authors of Mailman...
Hot on the heels of Mailman 2.0.7, I'm now releasing 2.0.8 which fixes
several cross-site scripting security holes, and a few other minor bug
fixes. More information on cross-site scripting exploits in general can
be found at
I recommend anybody running a version of Mailman up to, and including
2.0.7 to upgrade to version 2.0.8.
I've made both full source tarballs and patches available. Actually,
patches going all the way back to 2.0 are now available on SourceForge.
for links to download all the patches and the source tarball. If you
decide to install the patches, please do read the release notes first:
Currently the SourceForge and www.list.org sites are up-to-date, and I
expect the gnu.org site to be updated soon.
I've also included links on the FAQ page to the Mailman FAQ wizard.
Thanks everybody for contributing good entries! (I may do some reorg
when I get a chance.) See the FAQ wizard at
Version-Release number of selected component (if applicable):
Steps to Reproduce:
See Description for details.
Errata has been released: https://www.redhat.com/support/errata/RHSA-2001-168.html