Greetings,
The security fix to map_yp_alias in 1.4.18 turned out to be incomplete. We
also expierenced some regressions in the updated filter plugin. Both are
addressed in this new release 1.4.19 which contains a few other small fixes
aswell.
If you do not use map_yp_alias or the filters plugi
Hello All,
The SquirrelMail team is happy to announce the release 1.4.16. The most
notable change is that cookies are now sent with the secure attribute set for
HTTPS-connections, meaning that they cannot leak to an HTTP-connection on the
same SquirrelMail installation. For details see the incl
Hello All,
It's a pleasure to be able to announce the release of SquirrelMail 1.4.15,
which is a bugfix release. It contains an assortment of bugfixes that have
been made during the past months by the SquirrelMail team.
The latest release can be downloaded from the SquirrelMail website at
http:
Hello All,
It's a pleasure to be able to announce the availability of the first Release
Candidate of SquirrelMail 1.4.15. A release candidate is intended as the
final public verification that a version is all right before it's
declared "stable". Please try it out and report any bugs to us.
The
Hi All,
> 869bece15e1aefe3769269e222bf7e0f squirrelmail-1.4.11.tar.gz
This file was accidentally generated incorrectly (it was not gzipped, only
tarred). I've fixed that now, but that also means the md5sum has changed:
b2768e991a688eb27793d3abde5720a2 squirrelmail-1.4.11.tar.gz
I'm sorry for
Hello All,
It's a pleasure to be able to announce the release of SquirrelMail 1.4.11,
which is a bugfix and stability release. It contains an assortment of
bugfixes that have been made during the past months by the SquirrelMail team,
and improves the handling of strangely-formed mail messages o
On Wednesday 16 May 2007 19:19, zamri wrote:
> Hi all,
>
> The high priority symbol (!) not shown in my message list. I use SM 1.4.9a
> on Mandriva Linux 2006 x86_64. Any pointer?
Hi,
Could you please send me the message that has this problem as an attachment?
(Use Forward as Attachment in Squir
On Tue, May 15, 2007 10:42, Thijs Kinkhorst wrote:
> I propose to fix it with attached patch. That should catch every deranged
> header we might encounter.
Committed as r12396 in stable.
Thijs
-
This SF.net em
On Tuesday 15 May 2007 09:10, Tomas Kuliavas wrote:
> "If delimiter contains a value that is not contained in string, then
> explode() will return an array containing string."
>
> is_array() test is useless. $type is always array.
Yes. I think that code was an error that was never corrected. The l
ad8ebe94d8d803b squirrelmail-1.4.10a.tar.gz
298aaa1811b3fb40a803a6f57b22be20 squirrelmail-1.4.10a.tar.bz2
feedb1456d03c4e9723e9b32318aa636 squirrelmail-1.4.10a.zip
Download at:
http://www.squirrelmail.org/download.php
Happy SquirrelMailing!
--
Thijs Kinkhorst
SquirrelMail Project Team
pg
On Wednesday 9 May 2007 19:59, Tomas Kuliavas wrote:
> Matthew Daubenspeck oddprocess.org> writes:
> > I just upgraded to 1.4.10 and it seems to have broken the settings for
> > Personal Information. It now ignores the settings for Full Name, E-mail
> > Address, and Reply To.
> >
> > It does, howe
l.org/download.php
Happy SquirrelMailing!
--
Thijs Kinkhorst
SquirrelMail Project Team
pgpKVahScemhB.pgp
Description: PGP signature
-
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 ex
oad at:
http://www.squirrelmail.org/download.php
Happy SquirrelMailing!
--
Thijs Kinkhorst
SquirrelMail Project Team
signature.asc
Description: This is a digitally signed message part
-
Take Surveys. Earn Cash. Influenc
.
We'd like to thank James Bercegay of GulfTech Security Research for
finding this issue and reporting it to us.
Happy SquirrelMailing!
Thijs Kinkhorst
on behalf of the SquirrelMail team
signature.asc
Description: This is a digitally
The SquirrelMail team is happy to announce that a testing version has
been released for the stable series: 1.4.6 Release Candidate 1. This
release candidate addresses many bugs found since the release of our
previous version.
Details on all the changes in this release can be found in the
ChangeLo
Hey people,
First of all, sorry for the stupid mistake in the first version of RC1,
luckily this was quickly fixed by Jonathan.
I'd like to point out that the CVS snapshots have been updated with the
security fixes. So those of you who run 1.5.0 should upgrade to the
latest snapshot.
regards,
T
On Sun, February 20, 2005 22:26, H Gilmer said:
> 1. Why can't the "purge" link be permanent instead of disappearing
> and needing to be refreshed, like any "empty trash" button anywhere
> else?
This seems like a really good idea to me. If there are no objections to
this I will implement this in
h for finding this very specific issue and
reporting it to the Debian SquirrelMail maintainers.
The CVE-id assigned to this bug is CAN-2005-0152.
Happy SquirrelMailing!
Thijs Kinkhorst
---
This SF.Net email is sponsored by: IntelliVIEW -- Interac
Hello people,
> I'm pleased to announce we have released SquirrelMail 1.4.4 Release
> Candidate 1 for testing. In this release there is a long list of fixes,
> updates, and changes, including some security updates.
Of this release a Debian package has been created and placed in the
experimental
On Thu, August 19, 2004 4:19, Jonathan Angliss said:
>> A sample mail:
>> Return-Path: <>
>>
>
> I don't think we put that there. I cannot find any code that sets the
> Return-Path. If you want a fix, you can add the code in
> src/compose.php, I'll go over the RFCs, and make sure we put it in
Hello all,
> The above isn't really about SquirrelMail, but Debian, so maybe you'll
> receive better answers at a Debian related list, or if you mail the
> packet maintainer, Sam Johnston (I won't give his mail address here, but
> it's on the Debian packet pages).
Sam hasn't responded to any bug
> One of our users has a Mac. He uses IE 4.5 to access Squirrelmail.
> When he tries to send a *.DOC File (which he supposedly generated on
> his Mac), then this file gets sent using the MIME Type
>
> "application/x-macbinary".
>
> and none of his correspondents can open it. Why is that?
> How can
>> We have found that the following lines of code from SquirrelMail are
>> vulnerable to script injection. We have listed them below. If you'd
>> like more detailed information, please feel welcome to e-mail me.
>> More importantly, if you intend to patch this vulnerability in the
>> future, please
> Is the attachment size configuration an adminstrative configuration?
The limit is based on limitations set in PHP: post_max_size,
upload_max_filesize and memory_limit. The minimum of those 3 vars
determines the limit reported by SquirrelMail.
Thijs
---
> Can squirrelmail be installed on a separate box than where qmail/vpopmail
> is
> installed?
Yes it can. For both the IMAP and SMTP servers you can supply a hostname
to connect to.
Thijs
---
This SF.net email is sponsored by: VM Ware
With V
Hello Chris,
> upload_max_filesize = 25M ; define the maximum allowed upload size
> max_execution_time = 1000 ; set a decent maximum execution time to
> ; allow long uploads or downloads
> memory_limit = 35M; must be a size > UL size
> post_max_size = 25M ;
> All of a sudden several of my users (including me) seem to have
> encountered some kind of bug. When the right_main page comes up, it only
> goes this far:
> After that, there is nothing. This seems to be where
Do you have display_errors set to On in php.ini?
It might be that something is causin
> Now my question is, why does the above file not have the $> matching
> bracket at the end? My squirrelmail 1.4.0.x install has it.
This is not really a problem; PHP doesn't require the files to end with ?>
for them to work just fine. Some people argue that it's better this way,
because in this
Hello Ralf,
> But the Folder generated in SquirrelMail was called "Sent.2003.Q2".
>
> I don't know how the user managed to create this folder, because if I
> use "Folders" and then try to create "Sent.2003.Q2", I get an error
> that the folder's name is invalid.
I don't know that either, because
> some of my users experienced a bug in squirrelmail 1.4: they had a
> message in their inbox with a illegal From: address, that contained a
> '<' , but without the terminating '>' (god knows how that happened)
Hello Maarten.
This has just been fixed last week, and will appear in the upcoming 1.4
Hello Benjamin,
> What I'm wondering is why isn't X-Mailer being inserted? Shouldn't there
> be one added that reads something like "X-Mailer: SquirrelMail 1.4.0"
The answer is in the spamassassin report:
> * 0.0 -- Has a User-Agent header
As you can see, we add a User-Agent header which obso
Hello Dave,
> New to SM and this list so sorry if this has been already covered.
You're quite right... this is a known problem that has been fixed in the
most recent snapshots. We plan to release a new version shortly. You can
find the snapshots at our website (squirrelmail.org) or you can choose
> to fix this error edit: download.php
> line 337 contains an extra ) after $passed_ent_id.
This is not present in the latest CVS version.
Please update to see if the problem goes away.
Thijs
---
This SF.net email is sponsored by: ValueWeb:
Hello Christian,
> I have seen this error just a couple of times (mainly from spam, I
> believe).
> It appears to come up when the From: address is incorrect. Below is the
> error message, along with the messages full headers. As you can see, the
> From: line contains only a name no actual
> Warning: Unknown(): Your script possibly relies on a session side-effect
> which existed until PHP 4.2.3.
This has been fixed recently. 1.4.0 is destined to be released soon, if
you can't wait or want to stick with the 1.2.x branch, you can download a
snapshot release from the website.
Thijs
number of changes as little as possible as not to
introduce new bugs.
Let me take this opportunity thank all of you who have helped us by
testing the code, submitting bug reports and suggesting fixes! Keep up the
good work!
Jonathan Angliss & Thijs Kinkhorst
SquirrelMail S
>> As a side note, it also runs fine over IPv6. But that was expectable.
>
> Why shouldn't it? SquirrelMail shouldn't care what the base protocol
> is... as long as it has PHP, the OS should handle the rest seemlessly.
Hence the "expectable"... it could have been that SquirrelMail does
something
> I've been attempting to get Squirrelmail working with the Dovecot IMAP
> server, with little success. I am able to read messages on the server,
> however when I try sending I get the following error.
You might want to consider upgrading your SquirrelMail installation.
You're currently using 1.0
Hello Tony,
> I have just upgraded to version 1.2.11 and one of my users had a problem
> with folders that contain a plus sign (+) in the the name; Squirrelmail
> returns an error "invalid mailbox".
>
> I have also just upgraded Courier-IMAP (their mailing list says that
> other mail clients work
Hallo Ruairi,
>Emails from my squirrelmail setup do not have a host name attached to
> the
> Message ID and are therefore rejected by some mailing lists (this one
> included)... Any idea as to the problem / solution ?
Thanks for reporting this. It seems your webserver doesn't set the
SERVER_
> Squirrelmail 1.2.x seems to have a problem with mailbox names containing
> an ampersand or ones that end in spaces (probably ones that begin with
> spaces as well). These are all legal names, I think.
Hello Bruce,
I'm curious if this is also the case in 1.4.0. If so, please file a
bugreport fo
Hello,
> I'm a new user of Squirrelmail (1.2.9), and was perusing the plugins
> collection looking for a way to delete a message while reading and proceed
> to the next/previous one. The Delete_move_next plugin looks like what I'd
> want, but it is listed in the "Obsolete" group, indicating that
> I would love to see how it _should_ have been done. I was under a time
> limit and knew you guys would probably have a better way to do it,
> unfortunately I was on my own with this one. Glad to have helped!
http://cvs.sf.net/cgi-bin/viewcvs.cgi/squirrelmail/squirrelmail/class/mime/Rfc822Heade
t for SquirrelMail!
Thijs Kinkhorst
SquirrelMail stable series team
---
This SF.NET email is sponsored by:
SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See!
http://www.vasoftware.com
--
squirrelmail-users mailing list
List Ad
>>> > SourceForge seemed to have messed up their CVS servers, so the
>>> unfortunately i have only tried in the last couple of days when it has
>>> been
>>> broken.
I have fixed the snapshot downloading on the website, from now there are
functioning snapshots on the usual spot again. Sorry for t
> What I am trying to accomplish is simply put a link below the "Login"
> button on the initial squirrel page. I want the link to say something
You might want to try this plugin:
http://www.squirrelmail.org/plugin_view.php?id=108
Thijs
---
> Warning: Undefined variable: imapConnecion in
> /export/var/www/squirrelmail-1.4.0-20030110-cvs/plugins/delete_move_next/setup.php
> on line 45
I've fixed this obvious typo in CVS. Should appear in the release on the
site within a day.
Thijs
--
>> - NS6.2 for linux is not formatting HTML properly (if at all)
> un-rendered HTML in Mozilla 1.1 on Linux
I can't reproduce this in Mozilla 1.1 or Phoenix 0.5. Can you indicate
exactly which HTML-part(s) is/are un-rendered?
Thijs
---
This
> Question: does the apache user need execution privileges? by using my
> permission set (700), am I risking a security breach?
Giving the folder execution permissions for apache means that apache can
get the directory listing for that folder. Apparently this is neccessary
for PHP to function cor
> I cannot rename or delete folders:
You are using SquirrelMail 1.2.7. Please upgrade to 1.2.10 first, as many
changes have been made since then.
Thijs
---
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.c
> Warning: stat failed for functions (errno=2 - No such file or directory)
> in
> /Websites/www.jmvtec.com/squirrelmail/functions/display_messages.php on
> line 50
This means that the webserver can't read your functions dir. Make sure
it's there and readable for the webserver.
Thijs
--
> Love the Christmas logo :)
> Are there ones for other holidays?
Just be patient and see :)
Thijs
---
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
--
squirrelmail-users mailing list
List Address
> Does anyone have a copy of the Squirrel logo with the Christmas
> stocking cap? I remember seeing either last year or the year
> before.
I just put it online on http://www.squirrelmail.org
Thanks for the tip :-)
Thijs
---
This SF.NET e
Hello Toby,
> This patch fixes a few grammatical errors -- apostrophes in the wrong
> places and such. Also, it replaces "appends" with "prepends" where the
> latter is more accurate.
Thanks, I've incorporated these fixes in the help files so they will be
part of the next release.
Thijs
-
> Has anybody noticed the latest article on www.squirrelmail.org? It
> talks about the site being hacked. Is that accurate? Was that article
> really posted by a hacker?
Yes. This was a problem in the setup that SourceForge uses. We're looking
into a way of solving this issue. Unfortunately, th
> Is SquirrelMail v1.2.10 vulnerable to the recent discovered XSS bugs in
> SquirrelMail v1.2.9???
Yes it is. We are working out a decent solution. However, I think it
should be noted that the implications of this bug are (in my opinion) very
small.
Thijs
> Does anyone have any suggestions as to how to gracefully handle these
> kind of mails? I could configure the MTA to reject mail with > arbitrary number> of accounts listed in the To: field, but I don't want
> to go against the RFCs.
This problem has been reported before. I think the parsing cod
> hello... i have problems after install sm 1.2.9... with previous- next
> in all folders
>
> but with 1.2.8 have not this problem
Please try 1.2.10.
Thijs
---
This SF.net email is sponsored by: Get the new Palm Tungsten T
handheld. Powe
Erik,
> Fatal error: Failed opening required '../src/validate.php'
> (include_path='') in
> /var/www/avondel.nl/squirrelmail-1.3.2/plugins/calendar/admin_options.php
> on line 11
Your problem might be that validate.php has been moved to the include/
directory, so you need to change the re
> Hello Deano!,
> On Thursday, November 28, 2002, Deano! wrote...
>
>> Anyone have a rough ETA for 1.4? I really need stable Japanese
>> language support, with all the nice plugins.
>
> I think we'll be working on the 1.4 series soon, couldn't give an
> exact date yet though. We're just working on
> How do I disable the "feature" that hides most of the TO and CC
> addresses when you read an email.
This is not possible at the moment. You may want to submit this as a
feature request:
http://sourceforge.net/tracker/index.php?group_id=311&atid=350311
Thijs
--
> "Strange, your old password doesn't match the database... rejecting."
>
> the pages just refreshes with this error
> i am running qmail SM 1.2.9 courier- imap vpopmail and mysql
Hello,
Do you have register_globals off or on?
Thijs
---
This
> Is there any way to log the activity of users or track who has logged in
> and when? I see there is a plugin for tracking when you last logged in
> and your name etc. But I want an administrative logging or tracking
> method? Is there anything like that?
I think you're looking for this:
http:
Hello Magnus,
> I've got the delete_move_next plugin install, any chance of it to be
> better intergrated,
In the development version, there are plans to better integrate this
plugin. I don't think this will happen in the current 1.2 series though.
> My second problem is the Priority header, is
64 matches
Mail list logo