diff options
author | Yasuhito FUTATSUKI at POEM <futatuki@poem.co.jp> | 2020-07-01 14:07:54 +0900 |
---|---|---|
committer | Yasuhito FUTATSUKI at POEM <futatuki@poem.co.jp> | 2020-07-01 14:07:54 +0900 |
commit | 35d1ad5dc3acef79d1dca756c76bf2198acbbcb3 (patch) | |
tree | f8484aab620e40a549993c8eeefc02a399bd1ff5 /NEWS | |
parent | 77ba23b721bbd94a660d44edf72f47c0e58b07ae (diff) | |
parent | ed5f68f60484c62be8fc463ef433175e99f11f2f (diff) | |
download | mailman2-35d1ad5dc3acef79d1dca756c76bf2198acbbcb3.tar.gz mailman2-35d1ad5dc3acef79d1dca756c76bf2198acbbcb3.tar.xz mailman2-35d1ad5dc3acef79d1dca756c76bf2198acbbcb3.zip |
sync merge lp:mailman/2.1 up to 1859 (2.1.34 release)
Diffstat (limited to 'NEWS')
-rw-r--r-- | NEWS | 16 |
1 files changed, 12 insertions, 4 deletions
@@ -5,7 +5,7 @@ Copyright (C) 1998-2020 by the Free Software Foundation, Inc. Here is a history of user visible changes to Mailman. -2.1.34 (xx-xxx-xxxx) +2.1.34 (26-Jun-2020) i18n @@ -20,18 +20,25 @@ Here is a history of user visible changes to Mailman. - DMARC mitigation no longer misses if the domain name returned by DNS contains upper case. (LP: #1881035) + - A new WARN_MEMBER_OF_SUBSCRIBE setting can be set to No to prevent + mailbombing of a member of a list with private rosters by repeated + subscribe attempts. (LP: #1883017) + + - Very long filenames for scrubbed attachments are now truncated. + (LP: #1884456) + 2.1.33 (07-May-2020) Security - A content injection vulnerability via the private login page has been - fixed. (LP: #1877379) + fixed. CVE-2020-15011 (LP: #1877379) 2.1.32 (05-May-2020) i18n - Fixed a typo in the Spanish translation and uptated mailman.pot and + Fixed a typo in the Spanish translation and updated mailman.pot and the message catalog for 2.1.31 security fix. 2.1.31 (05-May-2020) @@ -39,7 +46,8 @@ Here is a history of user visible changes to Mailman. Security - A content injection vulnerability via the options login page has been - discovered and reported by Vishal Singh. This is fixed. (LP: #1873722) + discovered and reported by Vishal Singh. This is fixed. CVE-2020-12108 + (LP: #1873722) i18n |