https://issues.apache.org/SpamAssassin/show_bug.cgi?id=2536

Mark Martinec <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |[email protected]

--- Comment #38 from Mark Martinec <[email protected]> 2009-09-17 16:47:22 
PDT ---
> Patch works fine but you need to untaint $dir so mkdir works.

Bug 6206, Bug 2536: spamd: untaint directory as obtained from
a password file or from vpopmail utilities, avoid implicit
untainting; report error if user preferences file exists
but cannot be accessed; some cosmetics (avoid deep nesting
where possible, and avoid faraway small code segments)
  Sending        lib/Mail/SpamAssassin.pm
  Sending        spamd/spamd.raw
Committed revision 816412.


Is this now fixed?

-- 
Configure bugmail: 
https://issues.apache.org/SpamAssassin/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.

Reply via email to