Hello David,
On Monday, June 23, 2003, David Rees wrote...

> I verified the exploits on 1.2.11.  They don't appear to work on 1.4.0:

> http://www.securityfocus.com/bid/7952/exploit/

Well apart from the the privalages escilation at the bottom, these
errors have NOTHING to do with squirrelmail at all.  It's a "Feature"
of UW-IMAP.  This was pointed out ages ago, to which I even pointed
out the UW-IMAP FAQ page, to which I shall point out AGAIN.

  http://www.washington.edu/imap/IMAP-FAQs/index.html#5.1

So... no... those are invalid bugs... the author didn't investigate
the first few issues correctly.

-- 
Jonathan Angliss
([EMAIL PROTECTED])



-------------------------------------------------------
This SF.Net email is sponsored by: INetU
Attention Web Developers & Consultants: Become An INetU Hosting Partner.
Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission!
INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php
--
squirrelmail-users mailing list
List Address: [EMAIL PROTECTED]
List Archives:  http://sourceforge.net/mailarchive/forum.php?forum_id=2995
List Info: https://lists.sourceforge.net/lists/listinfo/squirrelmail-users

Reply via email to