Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 10264 - dev-perl/MailTools
Summary: dev-perl/MailTools
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: x86 Linux
: Lowest critical (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2002-11-05 07:09 UTC by Daniel Ahlberg (RETIRED)
Modified: 2003-02-04 19:42 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Ahlberg (RETIRED) gentoo-dev 2002-11-05 07:09:12 UTC
The SuSE Security Team reviewed critical Perl modules, including the
    Mail::Mailer package. This package contains a security hole which allows
    remote attackers to execute arbitrary commands in certain circumstances.
    This is due to the usage of mailx as default mailer which allows commands
    to be embedded in the mail body.
      Vulnerable to this attack are custom auto reply programs or spam filters
    which use Mail::Mailer directly or indirectly.



version 1.51: Tue Oct 29 14:25:28 CET 2002

        - Mail::Util::maildomain() if no information about domains
          is found in sendmail.cf, no error should be reported.
          [Vaughn Skinner]

        - Removed the possibility to use 'mailx', which was the
          default: removal from the detectionn routines and Mail/Mailer/mail.pm.
          Strongly suggested by [Sebastian Krahmer]
Comment 1 Seemant Kulleen (RETIRED) gentoo-dev 2002-11-05 17:54:18 UTC
all yours, aliz
Comment 2 Alexander Holler 2002-11-06 18:18:02 UTC
The new MailTools has broken my email-server (amavis needs mailtools):  They got installed at the wrong place: >>> //usr/lib/5.6.1/ >>> /usr/lib/5.6.1/i686-linux/ >>> //usr/lib/5.6.1/i686-linux/perllocal.pod  >>> Regenerating /etc/ld.so.cache... >>> dev-perl/MailTools-1.51 merged.  This is really annoying, will that inc bug with perl never stop?  Just for other amavis-users: you won't receive any mails because amavis will bounce all mails because it couldn't find the needed perl headers.  
Comment 3 Alexander Holler 2002-11-06 18:46:13 UTC
I can't tell you how much I hate that perl mess.  
After I unmerged ExUtils-MakeMake and reemerged perl, 
the MailTools got installed at the right place.