[Bug 229351] japanese/mailman may be also affectd by JVN#00846677/JPCERT#97432283/CVE-2018-0618

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Tue Jun 26 17:13:58 UTC 2018


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=229351

            Bug ID: 229351
           Summary: japanese/mailman may be also affectd by
                    JVN#00846677/JPCERT#97432283/CVE-2018-0618
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Some People
          Priority: ---
         Component: Individual Port(s)
          Assignee: tota at FreeBSD.org
          Reporter: freebsd-bug-report-yf at yf.bsdclub.org
          Assignee: tota at FreeBSD.org
             Flags: maintainer-feedback?(tota at FreeBSD.org)

In GNU Mailman 2.1.27 release announcement, it contains fix of
JVN#00846677/JPCERT#97432283. 

I'm not sure which change between 2.1.26 and 2.17 are the fix of them, but they
may be rev 1747, rev 1754, and rev 1782.
(1747, 1754 from NEWS file changes, and 1782 from merge review comment)

https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/revision/1747
https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/revision/1754
https://code.launchpad.net/~futatuki/mailman/enhance-i18n-list-overview/+merge/348365/comments/909595

These may be applied against mailman 2.1.14+j7, and it may be able to make a
patch for them.

Alternatively, we can use release of my branch 2.1.27+j1, based on mailman
2.1.14+j7 and merged almost all changes in upstream, with some my own change.
(If it can be trusted my work :-).) 
Please see https://mm.poem.co.jp/#mailman-japan-poem for about it.

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the freebsd-ports-bugs mailing list