LWN.net Logo

Reports of procmail's death are not terribly exaggerated

Reports of procmail's death are not terribly exaggerated

Posted Nov 26, 2010 2:36 UTC (Fri) by ricky (subscriber, #45937)
Parent article: Reports of procmail's death are not terribly exaggerated

I don't think it's fair to portray CVE-2002-2034 and CVE-2006-5449 as
unfixed procmail vulnerabilities. These seem to be security issues
(lack of shell escaping) in an Email Sanitizer project and Horde, which
happen to use procmail, not procmail itself.


(Log in to post comments)

Reports of procmail's death are not terribly exaggerated

Posted Dec 22, 2010 20:29 UTC (Wed) by jhardin@impsec.org (guest, #15045) [Link]

> I don't think it's fair to portray CVE-2002-2034 ... as
> unfixed procmail vulnerabilities. These seem to be
> security issues (lack of shell escaping) in an
> Email Sanitizer project ...

No, it _isn't_ fair to portray CVE-2002-2034 as an unfixed procmail vulnerability, as it is neither unfixed (note the CVE entry says "_before_ 1.133") nor a vulnerability in procmail.

If you follow the links and look at the dates of the vulnerability reports and of the fix in the Sanitizer change log, you'll see that the vulnerability reports were generated from someone seeing in my change log that I had fixed a potential problem.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds