Hi Lionel, thanks for looking at this, I still consider it an important bug.
On Sun, Nov 13, 2005 at 06:33:05PM +0100, Lionel Elie Mamane wrote: > tags 244673 =upstream > I can't find a patch that seems to address one of these issues only > (or both issues) on your FTP directory. Which one are you referring to? As I wrote in my first submision: (Each patch has its own description in the top including the corresponding updstream bug numbers.) I can quote from the patches: http://ftp.intevation.de/users/bernhard/mailman/mailman-2.1.4-avoid-headerfolding-python21.diff Attempt to make Mailman leave signatures intact. Submessage parts will not get headers folded if the new Mailman.Generator.Generator class is used. Hopefully fixes, Mailman SF Bug: [ 815297 ] Breaking signatures in message/rfc822 attachement! > Additionally, that's an upstream issue. Could you please take that up > with upstream? I did a long while ago, as written before, see upstream bug number above. > (I'll gladly apply a patch to the Debian package once > we get upstream's take on it.) Upstream did not refute the priority "8" of the bug, but also did not react so far. As this is an obvious security issues in setting with signed emails I hope that others see the points. The patch improves the behavious, but does not completely solve all cases. A real fix will need to change the underlying library, so this is the bst I could do. I am running the patch in a few production sites, and I am acknowledged for Mailman development: http://cvs.sourceforge.net/viewcvs.py/mailman/mailman/ACKNOWLEDGMENTS?rev=HEAD Bernhard (Reiter)
signature.asc
Description: Digital signature