Updated Mailman packages are now available for Red Hat PowerTools 7 and7.1. These updates fix cross-site scripting bugs which might allow anotherserver to be used to gain a user's private information from a serverrunning Mailman.
These updates close a potential security hole which would present clientswith a listing of the contents of a directory instead of the contents of anindex file or the proper error message.
A potential security bug which would present clients with alisting of the contents of a directory instead of the contents of an indexfile, or in case of an error, the error message, has been fixed.
These updates fix a bug in handling of restricted keys which mayallow users to bypass command restrictions by using subsystems and a subtlebug which might aid a passive analysis attack.