From barry at python.org Sun Jan 26 16:56:38 2003 From: barry at python.org (Barry A. Warsaw) Date: Sun Jan 26 16:57:09 2003 Subject: [Mailman-Announce] Fix for cross-site scripting bug in Mailman 2.1.0 Message-ID: <15924.22934.672789.975426@gargle.gargle.HOWL> The cross-site scripting bug in Mailman 2.1.0 that was reported on Bugtraq has been fixed. My thanks to all who reported this (except unfortunately the person who posted it to bugtraq before contacting me first. :/ ). Special thanks to Tokio Kikuchi who worked out the essential fix. The patch is at: http://sourceforge.net/project/showfiles.php?group_id=103 (see the file xss-2.1.0-patch.txt) And the original Bugtraq announcement is here: http://online.securityfocus.com/archive/1/308154 This patch will be part of Mailman 2.1.1 which is nearing release. -Barry