Re: [Mailman-Developers] [Mailman-Users] any info on this reported exploit?

2006-01-30 Thread Tokio Kikuchi
Mark Sapiro wrote: > Tokio Kikuchi wrote: > >>We may have to patch against this email package parsedate bug. >>I've just uploaded a patch on SF tracker. Please someone review this >>before I commit in the CVS (this weekend, maybe). > > > I have looked at the patch in the tracker. > > Caveat:

Re: [Mailman-Developers] [Mailman-Users] any info on this reportedexploit?

2006-01-30 Thread Mark Sapiro
Tokio Kikuchi wrote: > >We may have to patch against this email package parsedate bug. >I've just uploaded a patch on SF tracker. Please someone review this >before I commit in the CVS (this weekend, maybe). I have looked at the patch in the tracker. Caveat: I haven't tested anything - this is

Re: [Mailman-Developers] [Mailman-Users] any info on this reportedexploit?

2006-01-30 Thread Tokio Kikuchi
Mark Sapiro wrote: > Tokio Kikuchi wrote: > >>We may have to patch against this email package parsedate bug. >>I've just uploaded a patch on SF tracker. Please someone review this >>before I commit in the CVS (this weekend, maybe). >>https://sourceforge.net/tracker/?func=add&group_id=103&atid=30

Re: [Mailman-Developers] [Mailman-Users] any info on this reportedexploit?

2006-01-30 Thread Mark Sapiro
Tokio Kikuchi wrote: > >We may have to patch against this email package parsedate bug. >I've just uploaded a patch on SF tracker. Please someone review this >before I commit in the CVS (this weekend, maybe). >https://sourceforge.net/tracker/?func=add&group_id=103&atid=300103 Above URI is not cor

Re: [Mailman-Developers] [Mailman-Users] any info on this reported exploit?

2006-01-30 Thread Tokio Kikuchi
Tokio Kikuchi wrote: >> http://www.securityfocus.com/bid/16248/discuss >> GNU Mailman Large Date Data Denial Of Service Vulnerability >> GNU Mailman is prone to a denial of service attack. This issue affects >> the >> email date parsing functionality of Mailman. (snip) >> 06.3.18 CVE: CVE-2005-41