I don't think it's fair to portray CVE-2002-2034 and CVE-2006-5449 as
unfixed procmail vulnerabilities. These seem to be security issues
(lack of shell escaping) in an Email Sanitizer project and Horde, which
happen to use procmail, not procmail itself.
Reports of procmail's death are not terribly exaggerated
Posted Dec 22, 2010 20:29 UTC (Wed) by jhardin@impsec.org (guest, #15045)
[Link]
> I don't think it's fair to portray CVE-2002-2034 ... as
> unfixed procmail vulnerabilities. These seem to be
> security issues (lack of shell escaping) in an
> Email Sanitizer project ...
No, it _isn't_ fair to portray CVE-2002-2034 as an unfixed procmail vulnerability, as it is neither unfixed (note the CVE entry says "_before_ 1.133") nor a vulnerability in procmail.
If you follow the links and look at the dates of the vulnerability reports and of the fix in the Sanitizer change log, you'll see that the vulnerability reports were generated from someone seeing in my change log that I had fixed a potential problem.