http://bugzilla.spamassassin.org/show_bug.cgi?id=3325





------- Additional Comments From [EMAIL PROTECTED]  2004-05-01 12:24 -------
I don't think it matters, but just to check: what version of Net::DNS do you 
have installed?


I've been digging around and can't see where any tainted data could be though:

S23 > 6.2 && (time - S25 < 120*86400)

the whole string is from the config, which gets detainted when it's read in.  
it 
gets converted to the eval:

$sb{23} > 6.2 && (time - $sb{25} < 120*86400)

which would still be untainted as a whole.  %sb is untainted at creation time.  
so unless something magically gets tainted, or time is considered tainted 
(which 
would break a hell of a lot more code) ...



------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.

Reply via email to