Hello Jonathan,


I apologize, I had not paid attention to the extra space included in the

list of MAILTO addresses.


I suppose that we can sanitize the value of MAILTO, by checking it

with a regular _expression_ derived from RFC 5322 Official Standard

(see https://emailregex.com/), or do you suggest some lighter approach?


Best regards,                       Georges.



Jonathan H N Chin a écrit :
> Sorry, my mail server does not seem to have received any email
> from debian when you sent your email on 2024-01-21. Was I
> supposed to have been automatically Bcc'd?
>
> I disagree that the bug is not grave – I believe it meets the
> criterion of data being lost (and was in fact lost by the user).
> However, that does not really bother me.
>
> Note that I used quotation marks around the word unsafe because
> that is the wording used in the syslog message; the addresses are
> not unsafe. The problem is the space character.

Reply via email to