[Bug 4758] New: spamd with -u option should change uid earler

2006-01-10 Thread bugzilla-daemon
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4758 Summary: spamd with -u option should change uid earler Product: Spamassassin Version: 3.1.0 Platform: Other OS/Version: other Status: NEW Severity: normal

[Bug 4758] spamd with -u option should change uid earler

2006-01-10 Thread bugzilla-daemon
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4758 --- Additional Comments From [EMAIL PROTECTED] 2006-01-10 17:27 --- Created an attachment (id=3322) -- (http://issues.apache.org/SpamAssassin/attachment.cgi?id=3322action=view) Reverts back to 3.0.x behaviour for where were

[Bug 4758] spamd with -u option should change uid earler

2006-01-10 Thread bugzilla-daemon
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4758 --- Additional Comments From [EMAIL PROTECTED] 2006-01-10 18:11 --- the change was made specificially to fix other issues, such as sending a HUP (needs root to get port 783 back), reading config files, writing pid files,

[Bug 4758] spamd with -u option should change uid earler

2006-01-10 Thread bugzilla-daemon
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4758 --- Additional Comments From [EMAIL PROTECTED] 2006-01-10 19:35 --- There is just one problem - now parent preloads modules as root and this runs certain initialization routines. In particular it will initialize pyzor and

[Bug 4759] New: fetchmail marker, restarting parse can be used by spammers to hide relay handovers from SA

2006-01-10 Thread bugzilla-daemon
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4759 Summary: fetchmail marker, restarting parse can be used by spammers to hide relay handovers from SA Product: Spamassassin Version: SVN Trunk (Latest Devel Version) Platform:

[Bug 4759] fetchmail marker, restarting parse can be used by spammers to hide relay handovers from SA

2006-01-10 Thread bugzilla-daemon
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4759 [EMAIL PROTECTED] changed: What|Removed |Added Component|Libraries |Security Target

[Bug 4760] possible to be in internal_networks without being in trusted_networks

2006-01-10 Thread bugzilla-daemon
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4760 [EMAIL PROTECTED] changed: What|Removed |Added AssignedTo|dev@spamassassin.apache.org |[EMAIL PROTECTED]

[Bug 4636] Charset normalization plugin support

2006-01-10 Thread bugzilla-daemon
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4636 --- Additional Comments From [EMAIL PROTECTED] 2006-01-10 22:23 --- (In reply to comment #21) For these reasons, I am -1 (that is, vetoing) the current form of this code that has the performance loss and requires recoding.

[Bug 4759] fetchmail marker, restarting parse can be used by spammers to hide relay handovers from SA

2006-01-10 Thread bugzilla-daemon
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4759 [EMAIL PROTECTED] changed: What|Removed |Added Group|security| CC|

[Bug 4759] [review] fetchmail marker, restarting parse can be used by spammers to hide relay handovers from SA

2006-01-10 Thread bugzilla-daemon
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4759 [EMAIL PROTECTED] changed: What|Removed |Added Summary|fetchmail marker, |[review] fetchmail marker,

[Bug 4759] [review] fetchmail marker, restarting parse can be used by spammers to hide relay handovers from SA

2006-01-10 Thread bugzilla-daemon
http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4759 [EMAIL PROTECTED] changed: What|Removed |Added CC|[EMAIL PROTECTED]| |.org

Re: Security-related bugs

2006-01-10 Thread Robert Menschel
Hello Duncan, Tuesday, January 10, 2006, 4:52:41 PM, you wrote: DF So, here I'd like to outline the criteria I would suggest for DF determining whether a bug should be classified as security and DF restricted to the security team. Please comment. :-) Good. DF - Bugs which allow false

review reminder

2006-01-10 Thread Justin Mason
We need quite a lot of reviews on the 3.1.1 milestone. --j.

What's up with these URLs?

2006-01-10 Thread Theo Van Dinter
http://gz8l9a2f7cg3/?ra=XXDD http://kzbrdz2lj80ym/?ra=XXDD Clearly if it's just a hostname w/out domain it's not going to work ... So does this get parsed into something useful by some MUA/browser/etc? Both were found in a spam with a text/plain part only. Thoughts? (I replaced the cgi bits