On Mon, 2025-04-21 at 20:45 +0300, Valtteri Vuorikoski wrote: So at the moment it seems to me that the correct interpretation is c). Hard to tell because the modified source doesn't seem to be available in despite Mailman being GPL. Maybe someone needs to ask cPanel LLC to mail them a CD? cPanel's fork of mailman2-python3 is located here: https://github.com/cpanel/mailman2-python3
-Jim P.
On 2025-04-21 12:48, Valtteri Vuorikoski wrote: Are these vulnerabilities due to modifications made by the vendor (cPanel LLC) to their distributed version?
-Valtteri Direct quoting the CVE: Affected Software: GNU Mailman 2.1.39 (bundled with cPanel/WHM)
Especially if you can't reproduce it in pure MM 2.1.39.