From maintainer Nikolay Sturm <sturm@sec.informatik.tu-darmstadt.de>.
mailman changes:
- Implemented a guard against some reply loops and 'bot subscription
attacks. Specifically, if a message to -request has a Precedence:
bulk (or list, or junk) header, the command is ignored. Well-behaved
'bots should always include such a header.
- Changes to the configure script so that you can pass in the mail host
and web host by setting the environment variables MAILHOST and WWWHOST
respectively. configure will also exit if it can't figure out these
values (usually due to broken dns).
- Closed another minor cross-site scripting vulnerability.
Submitted by Nikolay Sturm <nikolay.sturm@desy.de>
---
This is GNU Mailman, a mailing list management system distributed
under the GNU Public License (GPL).
Mailman has most of the standard features you'd expect in a
mailing list manager, and more.