https://issues.apache.org/SpamAssassin/show_bug.cgi?id=2536
Mark Martinec <[email protected]> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |[email protected] --- Comment #38 from Mark Martinec <[email protected]> 2009-09-17 16:47:22 PDT --- > Patch works fine but you need to untaint $dir so mkdir works. Bug 6206, Bug 2536: spamd: untaint directory as obtained from a password file or from vpopmail utilities, avoid implicit untainting; report error if user preferences file exists but cannot be accessed; some cosmetics (avoid deep nesting where possible, and avoid faraway small code segments) Sending lib/Mail/SpamAssassin.pm Sending spamd/spamd.raw Committed revision 816412. Is this now fixed? -- Configure bugmail: https://issues.apache.org/SpamAssassin/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
