oss-sec mailing list archives

Re: 3 new CVE's in old branch of GNU mailman


From: "Jim P." <oss-security@jwp.email>
Date: Mon, 21 Apr 2025 14:37:55 -0400

On Mon, 2025-04-21 at 20:45 +0300, Valtteri Vuorikoski wrote:

So at the moment it seems to me that the correct interpretation is c). Hard to
tell because the modified source doesn't seem to be available in despite Mailman
being GPL. Maybe someone needs to ask cPanel LLC to mail them a CD?

cPanel's fork of mailman2-python3 is located here: 
https://github.com/cpanel/mailman2-python3


-Jim P.


Current thread: