-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 09 Sep 2021 14:24:36 +0200 Source: postorius Architecture: source Version: 1.2.4-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian Mailman Team Changed-By: Jonas Meurer Changes: postorius (1.2.4-1+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2021-40347: Check a user owns the email they are trying to unsubscribe (Fixes: #993746) Checksums-Sha1: 1af7ca22825e3365140689e37afa8e4e8f004c85 2597 postorius_1.2.4-1+deb10u1.dsc cc9a23ba7df5ef89a3a9ecf0833a18a01d05fc91 451043 postorius_1.2.4.orig.tar.gz 752ea612092023123959eb7fba5fe53c6bb1c8c9 801 postorius_1.2.4.orig.tar.gz.asc 068790a658dc08980e7fe422608ab33728a273ce 98088 postorius_1.2.4-1+deb10u1.debian.tar.xz 33fca9c4fbc66d80fbb2c8d7435b0d3e3ca2852c 8342 postorius_1.2.4-1+deb10u1_amd64.buildinfo Checksums-Sha256: e7b8ac6c78b0a880522dbc33c229f8d8d2d97fd44787daac68a15ce942061ab1 2597 postorius_1.2.4-1+deb10u1.dsc d4a52727079cd32e134a8aa741325dafb48a4303a815f762e388baceb4a5429c 451043 postorius_1.2.4.orig.tar.gz 6c589ef3c6a8a811efebb8b709d22dd15f1e954d71c64af55311c3a634705238 801 postorius_1.2.4.orig.tar.gz.asc 301d13a5cf44f677b6fe464d2cf8e1f933d60f3be87e72892ec63df08b9a90f4 98088 postorius_1.2.4-1+deb10u1.debian.tar.xz 9b11e62969cc88433d8a578c947546159508beaa25ba4b598ea102bfa4055196 8342 postorius_1.2.4-1+deb10u1_amd64.buildinfo Files: 4d51433d55a133563b185896ee1ea0a2 2597 python optional postorius_1.2.4-1+deb10u1.dsc fa86f0950e12ffc3a1ec672551865727 451043 python optional postorius_1.2.4.orig.tar.gz 5313e2e6ed4ec703eb61efc31a701ff4 801 python optional postorius_1.2.4.orig.tar.gz.asc 37f363b0cbdcaec018a74b77fb2d070b 98088 python optional postorius_1.2.4-1+deb10u1.debian.tar.xz bb492ef5ceb96e8c8b41c78cec5fc505 8342 python optional postorius_1.2.4-1+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEELIzSg9Pv30M4kOeDUmLn/0kQSf4FAmE6CwsACgkQUmLn/0kQ Sf4DCQ//T0iHBrweQPLVOP3pSMMHtbAwR/pGUNrmLwEtugrzpduCFxzF0UjqglQ8 uHxRcIOyt6liyIrX6IZxnINlXI9xLADWj0Z/ocQpxtuJg7wLVWdRL5cIqUEjB4H5 +NJoarbGyAimq86tdefthLyJ0BE+1p/c1hOtcYnOqaLH+PRfOlfxpulujFKoH/mT oH2Ah1XsdIMMK8HC3tCuluHXX750NNynEPaKe68lA+PsoL2xSTKya1fBArVbKG0x bgd32zAQmyIat2/Ov5E6psL9bpeZRqUctpUXRnmqVqcI5P6KffH4qLWST+03xaeW S17TRdf0dd7NY4RoIy9QCzbzmd2tx+phLhOAgOHjUCHLVcY3SXHsSzVGOdh0aaf5 sZf6uGX11aJtUx0DiXM+GtdT6n1k3T7NP2fnMZc8k/4DqQXkPq15zFb6WwBqHYPq uV1JE00xmr180gOB6p29EXrqQltmk0nyvdPQsAwQgXMJjX0dJOd3cSOy79R0PaUD aViLsluJoip3yjCb6N0Jie5nlTOJ8wnkKO/GRclQJiVJH0tsLPr7wLNzAESAw+Nx gzgNyImhgMA2sc1kRFRv2tGCRY0IsO+/L611WsN9Q5sm7Qv7NQlYNfDEdGtk4BIs tfwg0cVbkHC1sfS52vf12+srscm6+pc6xekXAuSYStBzq+E3W6E= =pcHz -----END PGP SIGNATURE-----