From mark at msapiro.net Tue Jul 10 21:03:06 2018 From: mark at msapiro.net (Mark Sapiro) Date: Tue, 10 Jul 2018 18:03:06 -0700 Subject: [Mailman-i18n] Mailman 2.1.18 Security fix release Message-ID: <49581d63-1175-3802-6433-e5021d0782d2@msapiro.net> This is a heads up. There is a recently identified minor security issue in Mailman 2.1.27 and earlier. This is not something that allows permanent compromise or information leak from your site, but is something that needs to be fixed. This issue has been given CVE ID CVE-2018-13796. I plan to release Mailman 2.1.28 on 24 July, 2018 along with details of the issue and a patch to apply to earlier releases. This is just notification of that plan for those that need to plan ahead. Also, if you are a Mailman translator and you have any updates to your translation, please submit them in some form prior to 24 July so they can be incorporated in the release. -- Mark Sapiro The highway is for gamblers, San Francisco Bay Area, California better use your sense - B. Dylan -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 195 bytes Desc: OpenPGP digital signature URL: From futatuki at poem.co.jp Tue Jul 10 21:56:02 2018 From: futatuki at poem.co.jp (Yasuhito FUTATSUKI) Date: Wed, 11 Jul 2018 10:56:02 +0900 Subject: [Mailman-i18n] Mailman 2.1.18 Security fix release In-Reply-To: <49581d63-1175-3802-6433-e5021d0782d2@msapiro.net> References: <49581d63-1175-3802-6433-e5021d0782d2@msapiro.net> Message-ID: <8ffac5c5-5d4c-ac8e-d088-56b189bd76f5@poem.co.jp> Hi, On 07/11/18 10:03, Mark Sapiro wrote: > Also, if you are a Mailman translator and you have any updates to your > translation, please submit them in some form prior to 24 July so they > can be incorporated in the release. Rev 1789 commit contains new msgid "Edit this template for" for language selecter button. Please modify it appropriate English and update potfile (or replace it to "View this page in", as listinfo.py, options.py, and roster.py use). Regards, -- Yasuhito FUTATSUKI From mark at msapiro.net Tue Jul 10 23:13:16 2018 From: mark at msapiro.net (Mark Sapiro) Date: Tue, 10 Jul 2018 20:13:16 -0700 Subject: [Mailman-i18n] correction: Mailman 2.1.28 Security fix release In-Reply-To: <49581d63-1175-3802-6433-e5021d0782d2@msapiro.net> References: <49581d63-1175-3802-6433-e5021d0782d2@msapiro.net> Message-ID: <106e27ee-73ba-fc83-bb22-4d6f3d34340f@msapiro.net> Resending with correct subject (2.1.28, not 2.1.18) On 7/10/18 6:03 PM, Mark Sapiro wrote: > This is a heads up. There is a recently identified minor security issue > in Mailman 2.1.27 and earlier. This is not something that allows > permanent compromise or information leak from your site, but is > something that needs to be fixed. This issue has been given CVE ID > CVE-2018-13796. > > I plan to release Mailman 2.1.28 on 24 July, 2018 along with details of > the issue and a patch to apply to earlier releases. > > This is just notification of that plan for those that need to plan ahead. > > Also, if you are a Mailman translator and you have any updates to your > translation, please submit them in some form prior to 24 July so they > can be incorporated in the release. -- Mark Sapiro The highway is for gamblers, San Francisco Bay Area, California better use your sense - B. Dylan -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 195 bytes Desc: OpenPGP digital signature URL: From mark at msapiro.net Wed Jul 11 00:32:39 2018 From: mark at msapiro.net (Mark Sapiro) Date: Tue, 10 Jul 2018 21:32:39 -0700 Subject: [Mailman-i18n] Mailman 2.1.28 Security fix release In-Reply-To: <8ffac5c5-5d4c-ac8e-d088-56b189bd76f5@poem.co.jp> References: <49581d63-1175-3802-6433-e5021d0782d2@msapiro.net> <8ffac5c5-5d4c-ac8e-d088-56b189bd76f5@poem.co.jp> Message-ID: On 7/10/18 6:56 PM, Yasuhito FUTATSUKI wrote: > Hi, > > On 07/11/18 10:03, Mark Sapiro wrote: >> Also, if you are a Mailman translator and you have any updates to your >> translation, please submit them in some form prior to 24 July so they >> can be incorporated in the release. > > Rev 1789 commit contains new msgid "Edit this template for" for language > selecter button. Please modify it appropriate English and update potfile > (or replace it to "View this page in", as listinfo.py, options.py, > and roster.py use). Thanks for the reminder. I think the English "Edit this template for" is OK as is. The mailman.pot has been updated at . -- Mark Sapiro The highway is for gamblers, San Francisco Bay Area, California better use your sense - B. Dylan From mark at msapiro.net Wed Jul 11 10:02:27 2018 From: mark at msapiro.net (Mark Sapiro) Date: Wed, 11 Jul 2018 07:02:27 -0700 Subject: [Mailman-i18n] Mailman 2.1.18 Security fix release (date change) In-Reply-To: <49581d63-1175-3802-6433-e5021d0782d2@msapiro.net> References: <49581d63-1175-3802-6433-e5021d0782d2@msapiro.net> Message-ID: <7a73d4eb-2db6-90b8-fa23-c65a930817a2@msapiro.net> On 7/10/18 6:03 PM, Mark Sapiro wrote: > This is a heads up. There is a recently identified minor security issue > in Mailman 2.1.27 and earlier. This is not something that allows > permanent compromise or information leak from your site, but is > something that needs to be fixed. This issue has been given CVE ID > CVE-2018-13796. > > I plan to release Mailman 2.1.28 on 24 July, 2018 along with details of > the issue and a patch to apply to earlier releases. > > This is just notification of that plan for those that need to plan ahead. Due to changed circumstances, I am changing the planned release date from 24 July to 23 July. -- Mark Sapiro The highway is for gamblers, San Francisco Bay Area, California better use your sense - B. Dylan -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 195 bytes Desc: OpenPGP digital signature URL: From Ralf.Hildebrandt at charite.de Wed Jul 18 04:33:18 2018 From: Ralf.Hildebrandt at charite.de (Ralf Hildebrandt) Date: Wed, 18 Jul 2018 10:33:18 +0200 Subject: [Mailman-i18n] Translation patch for German against mailman-2.1.27 Message-ID: <20180718083318.GE25626@charite.de> I heard of the upcoming release of mailman-2.1.28, so I thought it would be worthwhile to submit some patches. Attached is one small patch which fixes a lot of "msgfmt" warnings and fixes the German translation in one place. -- Ralf Hildebrandt Charite Universit?tsmedizin Berlin ralf.hildebrandt at charite.de Campus Benjamin Franklin https://www.charite.de Hindenburgdamm 30, 12203 Berlin Gesch?ftsbereich IT, Abt. Netzwerk fon: +49-30-450.570.155 -------------- next part -------------- A non-text attachment was scrubbed... Name: mailman.po.patch Type: text/x-diff Size: 2426 bytes Desc: not available URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 195 bytes Desc: not available URL: From mark at msapiro.net Wed Jul 18 16:31:41 2018 From: mark at msapiro.net (Mark Sapiro) Date: Wed, 18 Jul 2018 13:31:41 -0700 Subject: [Mailman-i18n] Translation patch for German against mailman-2.1.27 In-Reply-To: <20180718083318.GE25626@charite.de> References: <20180718083318.GE25626@charite.de> Message-ID: <4df6ed4f-8877-1c81-3a97-b2d2ad7a6588@msapiro.net> On 07/18/2018 01:33 AM, Ralf Hildebrandt wrote: > I heard of the upcoming release of mailman-2.1.28, so I thought it > would be worthwhile to submit some patches. > > Attached is one small patch which fixes a lot of "msgfmt" warnings and > fixes the German translation in one place. Thank you for the update. -- Mark Sapiro The highway is for gamblers, San Francisco Bay Area, California better use your sense - B. Dylan -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 181 bytes Desc: OpenPGP digital signature URL: From mark at msapiro.net Mon Jul 23 13:33:12 2018 From: mark at msapiro.net (Mark Sapiro) Date: Mon, 23 Jul 2018 10:33:12 -0700 Subject: [Mailman-i18n] Mailman 2.1.28 Security Release Message-ID: I am pleased to announce the release of Mailman 2.1.28. Python 2.6 is the minimum supported, but Python 2.7 is strongly recommended. This is a minor security fix release. It also has some i18n updates and a couple of bug fixes and adds the ability to edit list specific templates through the web admin UI in a supported language other than the list's default. See the attached README.txt for details. For details of the security issue, see the report at which also includes a patch for those who want to fix this issue without upgrading. Mailman is free software for managing email mailing lists and e-newsletters. Mailman is used for all the python.org and SourceForge.net mailing lists, as well as at hundreds of other sites. For more information, please see our web site at one of: http://www.list.org https://www.gnu.org/software/mailman http://mailman.sourceforge.net/ https://mirror.list.org/ Mailman 2.1.28 can be downloaded from https://launchpad.net/mailman/2.1/ https://ftp.gnu.org/gnu/mailman/ https://sourceforge.net/projects/mailman/ -- Mark Sapiro The highway is for gamblers, San Francisco Bay Area, California better use your sense - B. Dylan -------------- next part -------------- An embedded and charset-unspecified text was scrubbed... Name: README.txt URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 181 bytes Desc: OpenPGP digital signature URL: From mark at msapiro.net Tue Jul 24 18:59:08 2018 From: mark at msapiro.net (Mark Sapiro) Date: Tue, 24 Jul 2018 15:59:08 -0700 Subject: [Mailman-i18n] Mailman 2.1.29 Release Message-ID: I am not so pleased to announce the release of Mailman 2.1.29. It turned out there was a bug in the security fix in 2.1.28 that broke the web admin and listinfo overview pages. This is fixed in Mailman 2.1.29. The patch referred to below has been corrected to fix this bug. There is also a patch attached to which applies to 2.1.28 to fix this issue. Python 2.6 is the minimum supported, but Python 2.7 is strongly recommended. Mailman 2.1.28 was a minor security fix release. It also has some i18n updates and a couple of bug fixes and adds the ability to edit list specific templates through the web admin UI in a supported language other than the list's default. See the attached README.txt for details. For details of the security issue, see the report at which also includes a patch for those who want to fix this issue without upgrading. Mailman is free software for managing email mailing lists and e-newsletters. Mailman is used for all the python.org and SourceForge.net mailing lists, as well as at hundreds of other sites. For more information, please see our web site at one of: http://www.list.org https://www.gnu.org/software/mailman http://mailman.sourceforge.net/ https://mirror.list.org/ Mailman 2.1.29 can be downloaded from https://launchpad.net/mailman/2.1/ https://ftp.gnu.org/gnu/mailman/ https://sourceforge.net/projects/mailman/ -- Mark Sapiro The highway is for gamblers, San Francisco Bay Area, California better use your sense - B. Dylan -------------- next part -------------- An embedded and charset-unspecified text was scrubbed... Name: README.txt URL: