Roland Miyamoto | 28 Mar 13:24 2015
Picon
Picon

Re: Security patch and Mailman 2.1.20 to be released on 31 March


Thank you, Mark,

For this anouncement.
Does the vulnerabilitiy also affect older Mailman releases, like
2.1.15, e.g.?
If so, how do I make sure to incorporate the fix soon after next
Tuesday, when the world will learn about the details?

I am running Mailman 2.1.15 under Debian 7.
Will the fix be included in the usual repository updates?

  Best wishes

    Roland

On 27/03/15 22:42, Mark Sapiro wrote:
> A security vulnerability in Mailman has been found and fixed. It 
> has been assigned CVE-2015-2775.
Mark Sapiro | 27 Mar 18:47 2015
Picon

Re: Disable any notifications after user subscibes via LISTNAME-join <at> DOMAIN?

On 03/27/2015 03:22 AM, Danijel Domazet wrote:

(Please keep threads on the list unless there is some privacy reason not
to.)
> 
> One more question related to the same issue.
> 
> Here is the code I added to avoid auto reply:
> 
> field = msg.get('to', '')
>         if 'mylist-join' in field:
>             self.respond = False
> 
> I would like to check 'bcc' field instead of 'to', like so:
> field = msg.get('bcc', '')
> But that seems not to work.

Because Bcc: by definition does not appear in the headers of delivered mail.

The problem is you are testing the wrong thing. Instead of looking at
message headers, you should be looking for 'tojoin' in the msgdata which
is set when the mail is initially received be Mailman.

Instead of what you've done, I would do

--- Mailman/Queue/CommandRunner.py	2015-03-01 16:35:02 +0000
+++ Mailman/Queue/CommandRunner.py	2015-03-27 17:42:10 +0000
 <at>  <at>  -276,6 +276,8  <at>  <at> 
                 ret = res.process()
             elif msgdata.get('tojoin'):
(Continue reading)

Mark Sapiro | 26 Mar 15:50 2015
Picon

Re: Unwanted default entry in field "Your email address" in welcoming message

On 03/25/2015 02:08 PM, Paddy wrote:
> I am setting up a mailing list. When I add a subscriber by using the "Mass
> subscription" facility that subscriber receives a welcoming mail. That mail
> contains a paragraph "Subscribing to XY", "XY" being the name of the list.
> Within that paragraph there is a field "Your email address" and this field
> already contains a name (not an email address) which happens to be a
> username that I use in a related activity.

I responded about the list welcome message, but it seems you may really
be talking about the "listinfo" web page linked from the welcome email.

If what you are talking about is the email address field of the
subscribe form on that page, it is your web browser that's entering the
data in that field.

--

-- 
Mark Sapiro <mark <at> msapiro.net>        The highway is for gamblers,
San Francisco Bay Area, California    better use your sense - B. Dylan
------------------------------------------------------
Mailman-Users mailing list Mailman-Users <at> python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: https://mail.python.org/mailman/options/mailman-users/gmmu-mailman-users%40m.gmane.org

Mark Sapiro | 26 Mar 15:44 2015
Picon

Re: Unwanted default entry in field "Your email address" in welcoming message

On 03/25/2015 02:08 PM, Paddy wrote:
> I am setting up a mailing list. When I add a subscriber by using the "Mass
> subscription" facility that subscriber receives a welcoming mail. That mail
> contains a paragraph "Subscribing to XY", "XY" being the name of the list.
> Within that paragraph there is a field "Your email address" and this field
> already contains a name (not an email address) which happens to be a
> username that I use in a related activity. I've no idea where Mailman got it
> from and why it inserted it as a default into this email field. How do I
> restore this field to blank as default in the welcoming page ?

The default template for the list welcome email does not contain any
"Subscribing to ..." paragraph.

Check the

List-specific text prepended to new-subscriber welcome message
(Details for welcome_msg)

box on the list's General Options page, and go to the "Edit the public
HTML pages and text files" link on the upper right of the list's admin
pages and check the "Welcome email text file".

--

-- 
Mark Sapiro <mark <at> msapiro.net>        The highway is for gamblers,
San Francisco Bay Area, California    better use your sense - B. Dylan
------------------------------------------------------
Mailman-Users mailing list Mailman-Users <at> python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
(Continue reading)

Paddy | 25 Mar 22:08 2015
Picon

Unwanted default entry in field "Your email address" in welcoming message

I am setting up a mailing list. When I add a subscriber by using the "Mass
subscription" facility that subscriber receives a welcoming mail. That mail
contains a paragraph "Subscribing to XY", "XY" being the name of the list.
Within that paragraph there is a field "Your email address" and this field
already contains a name (not an email address) which happens to be a
username that I use in a related activity. I've no idea where Mailman got it
from and why it inserted it as a default into this email field. How do I
restore this field to blank as default in the welcoming page ?

Patrick

------------------------------------------------------
Mailman-Users mailing list Mailman-Users <at> python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: https://mail.python.org/mailman/options/mailman-users/gmmu-mailman-users%40m.gmane.org

Marco Stoecker | 26 Mar 11:11 2015
Picon

sync_members


Hi

I have several mailing lists on a Mailman server which are
synchronized with a database via a cronjob.

Now my question: is it possible to not only synchronize the e-mail
adresses but also the names?

BR
Marco
Mark Sapiro | 25 Mar 23:53 2015
Picon

Re: Disable any notifications after user subscibes via LISTNAME-join <at> DOMAIN?

On 03/25/2015 03:46 AM, Danijel Domazet wrote:
> Thanks Mark,
> 
> I tried to patch it with:
> self.respond = False
> but that didn't work.

Where did you put that line?

> Then I also tried to add immediate return from send_response, like so:
> 
> def send_response(self):
>         return
>         # Helper
>         def indent(lines):
>             return ['    ' + line for line in lines]
>         # Quick exit for some commands which don't need a response
>         if not self.respond:
>             return
> 
> 
> but that also didn't help.
> I regenerated pyc and pyo files too.

Two things: 1) regenerating .py[co] files is not necessary. Upon import
of a module, python will see the .py is newer and load and compile it
and if it has permission, write the .py[co] file it will use the next time.

2) More importantly, did you restart Mailman after making the changes?
You must do this. The qrunners are persistent processes and will not
(Continue reading)

Nancy Cullen | 24 Mar 21:33 2015
Picon

Scrubbing html

Hi, hoping someone can help me with settings. The group that I am 
listkeeper for just recently started
allowing html but our digest still shows this message at the end of each post:

An HTML attachment was scrubbed...

Thank you for any help!

Nancy

------------------------------------------------------
Mailman-Users mailing list Mailman-Users <at> python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: https://mail.python.org/mailman/options/mailman-users/gmmu-mailman-users%40m.gmane.org

David Benfell | 24 Mar 19:55 2015

virtual domain confusion

Hi all,

I'm trying to figure out virtual domains with mailman (and, yes,  
postfix). I have added

POSTFIX_STYLE_VIRTUAL_DOMAINS = ['humansci.org']

to my mm_cfg.py

But when I go to my administration page, I see no option to create a  
list under that domain. How is this supposed to be done?

Thanks!
--

-- 
David Benfell <benfell <at> parts-unknown.org>
------------------------------------------------------
Mailman-Users mailing list Mailman-Users <at> python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: https://mail.python.org/mailman/options/mailman-users/gmmu-mailman-users%40m.gmane.org
Danijel Domazet | 24 Mar 09:11 2015
Picon

Disable any notifications after user subscibes via LISTNAME-join <at> DOMAIN?

Hi Mailman users,
When a user tries to subscribe to the list by sending email to
LISTNAME-join <at> DOMAIN, he/she receives an email reply with subject "The
results of your email commands", etc.

Is there a way to disable any email notifications sent to the user after he
subscibes to the list via LISTNAME-join <at> DOMAIN?

Thanks,
Danijel
------------------------------------------------------
Mailman-Users mailing list Mailman-Users <at> python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: https://mail.python.org/mailman/options/mailman-users/gmmu-mailman-users%40m.gmane.org

Rafael Lamari | 24 Mar 14:04 2015
Picon

Information!!

Hello

Would anyone tell me if there are cases of Mailman Dicussion List 
integration with IBM Notes / Domino v9?

Thanks!!!

Rafael Lamari

"Esta mensagem, incluindo seus anexos, pode conter informação confidencial 
e/ou privilegiada. Portanto, fica o seu receptor notificado de que não 
deve usar, copiar, divulgar ou tomar qualquer atitude com base nestas 
informações. Se você recebeu esta mensagem por engano, solicitamos que 
você a apague. Quaisquer considerações ou opiniões contidas nesta mensagem 
pertencem somente ao autor remetente e não representam necessariamente a 
opinião da V&B Officeware, a não ser que esteja descrito explicitamente 
que o remetente está autorizado a representá-la. Grato pela sua 
colaboração."
------------------------------------------------------
Mailman-Users mailing list Mailman-Users <at> python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: https://mail.python.org/mailman/options/mailman-users/gmmu-mailman-users%40m.gmane.org


Gmane