Bug#946829: Patch works!

2020-01-10 Thread Magnus Holmgren
torsdag 19 december 2019 kl. 11:41:21 CET skrev du: > I can confirm that patch works as expected. > > Patch does not apply cleanly on my SA (3.4.2-1~deb9u2) but only for > cosmetic differences, attached a patch that wok on SA 3.4.2-1~deb9u2. > > > Thanks! I came up with the following RE loop to

Bug#946829: Patch works!

2019-12-19 Thread Marco Gaiarin
I can confirm that patch works as expected. Patch does not apply cleanly on my SA (3.4.2-1~deb9u2) but only for cosmetic differences, attached a patch that wok on SA 3.4.2-1~deb9u2. Thanks! -- dott. Marco Gaiarin GNUPG Key ID: 240A3D66 Associazione ``La N

Bug#946829: Patch

2019-12-18 Thread Henrik Krohns
Hello, This was really a vulnerability which allowed running any perl code or commands (even as root), for anyone able to write .cf files/rules. The bug is mitigated in SpamAssassin 3.4.3, which properly taints configuration strings, and results in Perl complaining and not running Greylisting.p