Bug#129104: cgiemail: buffer overflow and script reading vulnerabilities

2002-04-09 Thread Colin Watson
On Mon, Apr 08, 2002 at 11:00:06PM -0500, Thomas Smith wrote: > On Mon, Apr 08, 2002 at 02:50:18PM -0500, Colin Watson wrote: > > Better fixes are available, though. I'd forgotten that the last > > message in this bug left it up to me to test them ... I'll have a look > > today or tomorrow and see

Bug#129104: cgiemail: buffer overflow and script reading vulnerabilities

2002-04-08 Thread Thomas Smith
On Mon, Apr 08, 2002 at 02:50:18PM -0500, Colin Watson wrote: > Better fixes are available, though. I'd forgotten that the last > message in this bug left it up to me to test them ... I'll have a look > today or tomorrow and see if we can get this sorted. > > -- Colin Watson [EMAIL PROTECTED] Ther

Bug#129104: cgiemail: buffer overflow and script reading vulnerabilities

2002-04-08 Thread Colin Watson
On Mon, Apr 08, 2002 at 10:36:31AM -0400, Bruce R. Lewis wrote: > A recent message on debian-devel-announce shows cgiemail having been > removed from the upcoming release. > > Has the buffer overflow fix for cgicso been checked in? If not, one > option is to remove cgicso entirely, as it is reall

Bug#129104: cgiemail: buffer overflow and script reading vulnerabilities

2002-04-08 Thread Bruce R. Lewis
A recent message on debian-devel-announce shows cgiemail having been removed from the upcoming release. Has the buffer overflow fix for cgicso been checked in? If not, one option is to remove cgicso entirely, as it is really not useful except at MIT, and its existence probably confuses some peopl