GNU Mailman 2.1.27
Milestone information
- Project:
- GNU Mailman
- Series:
- 2.1
- Version:
- 2.1.27
- Released:
- Registrant:
- Mark Sapiro
- Release registered:
- Active:
- Yes. Drivers can target bugs and blueprints to this milestone.
Activities
- Assigned to you:
- No blueprints or bugs assigned to you.
- Assignees:
- 12 Mark Sapiro
- Blueprints:
- No blueprints are targeted to this milestone.
- Bugs:
- 12 Fix Released
Download files for this release
Release notes
2.1.27 (22-Jun-2018)
Security
- Existing protections against malicious listowners injecting evil
scripts into listinfo pages have had a few more checks added.
JVN#
- A few more error messages have had their values HTML escaped.
JVN#
- The hash generated when SUBSCRIBE_
the same as one generated at the same time for a different list and
IP address. While this is not thought to be exploitable in any way,
the generation has been changed to avoid this. Thanks to Ralf Jung.
New Features
- An option has been added to bin/add_members to issue invitations
instead of immediately adding members. (LP: #1773064)
- A new BLOCK_SPAMHAUS_
enable blocking web subscribes from IPv4 addresses listed in Spamhaus
SBL, CSS or XBL. It will work with IPv6 addresses if Python's
py2-ipaddress module is installed. The module can be installed via pip
if not included in your Python.
- Thanks to Jim Popovitch, Mailman has a new 'security' log and logs
authentic
data include the remote IP and can be used to automate blocking of IPs
with something like fail2ban. Since Mailman 2.1.14, these have returned
an http 401 status and the information should be logged by the web
server, but this new log makes that more convenient. Also, the
'mischief' log entries for 'hostile listname' noe include the remote IP
if available.
- Thanks to Jim Popovitch, admin notices of (un)subscribes now may give
the source of the action. This consists of a %(whence)s replacement
that has been added to the admin(un)
to Yasuhito FUTATSUKI for updating the non-English templates and help
with internationalizing the reasons.
- Thanks to Jim Popovitch, there is a new
BLOCK_
subscribes for addresses in domains listed in the Spamhaus DBL.
i18n
- The Japanese translation has been updated by Yasuhito FUTATSUKI.
- The Russian translation has been updated by Danil Smirnov.
- A partial Esperanto translation has been added. Thanks to
Rubén Fernández Asensio.
- Fixed a '# -*- coding:' line in the Russian message catalog that was
mistakenly translated to Russian. (LP: #1777342)
Miscellaneous
- Added to the contrib directory, a script from Jim Popovitch to generate
Sitemap files for a list's archive.