HomeFreeBSD

mail/mailman: security update to 2.1.31

Description

mail/mailman: security update to 2.1.31

Over the upstream 2.1.31, additional fixes were needed:
+ fix up quoting in one string of the messages/es/ translation

to unbreak gettext

+ fix up all */LC_MESSAGES/mailman.po to match up with the security fix.

Upstream Changelog for 2.1.31, cited from
https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/view/1845/NEWS#L8:
Security

  • A content injection vulnerability via the options login page has been discovered and reported by Vishal Singh. This is fixed. (LP: #1873722)

i18n

  • The Spanish translation has been updated by Omar Walid Llorente.

Bug Fixes and other patches

  • Bounce recognition for a non-compliant Yahoo format is added.
  • Archiving workaround for non-ascii in string.lowercase in some Python packages is added.

MFH: 2020Q2
Security: 88760f4d-8ef7-11ea-a66d-4b2ef158be83

Details

Provenance
mandreeAuthored on
Parents
rP534100: new mailman < 2.1.31 content injection vulnerability
Branches
Unknown
Tags
Unknown