I am a new maintainer of the mailman package on RHEL. I need to fix CVEs for it on Fedora.
ASAP
N/A
mailman affected by CVEs
mailman was retired 6 months ago, you will need a new package review to include it in Fedora.
Also note that packages using Python 2 are generally forbidden in Fedora, so if you want to include mailman, it would either need to run on Python 3 or get a FESCo approved exception.
I don't understand why would you need to fix CVEs in mailman in Fedora considering mailman is not included in Fedora. If you don't unretire mailman, it won't be affected by CVEs, it won't be existing. So I am a bit confused by this request.
Oh, I didn't know that! Thanks for your comment!
What I know is that mailman is affected on all/some fedora versions mentioned by Product Security Engineer (CVE-2021-42096, CVE-2021-42097) and it got tracker BZs created:
https://bugzilla.redhat.com/show_bug.cgi?id=2020569 [all] https://bugzilla.redhat.com/show_bug.cgi?id=2020576 [f33] https://bugzilla.redhat.com/show_bug.cgi?id=2020577 [f34]
I will discuss further internally.
mailman exists on f34 and f33. You may wish to "unorphan" the package (become the maintainer) and fix the CVEs there without unretiring it (resurrecting it on rawhide and/or f35). Is that what you had in mind?
I am sorry for the confusion! It looks that the component in those BZs should have been mailman3, but not the mailman.
Closing this. Thank you for your help!
Metadata Update from @mosvald: - Issue close_status updated to: Fixed with Explanation - Issue status updated to: Closed (was: Open)