OpenPKG CVS Repository
http://cvs.openpkg.org/
____________________________________________________________________________
Server: cvs.openpkg.org Name: Thomas Lotterer
Root: /e/openpkg/cvs Email: [EMAIL PROTECTED]
Module: openpkg-src openpkg-web Date: 19-Feb-2003 11:04:09
Branch: HEAD Handle: 2003021910040503
Modified files:
openpkg-src/majordomo majordomo.patch majordomo.spec
openpkg-web news.txt
Log:
fix from http://www.securityfocus.com/bid/6761
Summary:
Revision Changes Path
1.2 +14 -0 openpkg-src/majordomo/majordomo.patch
1.29 +1 -1 openpkg-src/majordomo/majordomo.spec
1.3357 +1 -0 openpkg-web/news.txt
____________________________________________________________________________
patch -p0 <<'@@ .'
Index: openpkg-src/majordomo/majordomo.patch
============================================================================
$ cvs diff -u -r1.1 -r1.2 majordomo.patch
--- openpkg-src/majordomo/majordomo.patch 19 Dec 2002 10:57:26 -0000 1.1
+++ openpkg-src/majordomo/majordomo.patch 19 Feb 2003 10:04:07 -0000 1.2
@@ -12,3 +12,17 @@
s/^~/~~/;
print MAIL $_;
}
+--- majordomo.orig Mon Feb 3 13:23:45 2003
++++ majordomo Mon Feb 3 13:23:23 2003
+@@ -624,6 +624,11 @@
+
+ sub do_which {
+ local($subscriber) = join(" ", @_) || &valid_addr($reply_to);
++ if ($subscriber !~ /^[0-9a-zA-Z\.\-\_]+\@[0-9a-zA-Z\.\-]+\.[a-zA-Z]{2,3}$/) {
++
++ &log("which abuse -> $subscriber passed as an argument.");
++ exit(0);
++ };
+ local($count, $per_list_hits) = 0;
+ # Tell the requestor which lists they are on by reading through all
+ # the lists, comparing their address to each address from each list
@@ .
patch -p0 <<'@@ .'
Index: openpkg-src/majordomo/majordomo.spec
============================================================================
$ cvs diff -u -r1.28 -r1.29 majordomo.spec
--- openpkg-src/majordomo/majordomo.spec 14 Jan 2003 14:43:32 -0000 1.28
+++ openpkg-src/majordomo/majordomo.spec 19 Feb 2003 10:04:08 -0000 1.29
@@ -33,7 +33,7 @@
Group: Mail
License: Majordomo License Agreement
Version: 1.94.5
-Release: 20030114
+Release: 20030219
# list of sources
Source0:
http://www.greatcircle.com/majordomo/%{version}/majordomo-%{version}.tar.gz
@@ .
patch -p0 <<'@@ .'
Index: openpkg-web/news.txt
============================================================================
$ cvs diff -u -r1.3356 -r1.3357 news.txt
--- openpkg-web/news.txt 19 Feb 2003 09:12:34 -0000 1.3356
+++ openpkg-web/news.txt 19 Feb 2003 10:04:05 -0000 1.3357
@@ -1,3 +1,4 @@
+19-Feb-2003: Upgraded package: P<majordomo-1.94.5-20030219>
19-Feb-2003: Upgraded package: P<vim-6.1.342-20030219>
19-Feb-2003: Upgraded package: P<tidy-20030217-20030219>
19-Feb-2003: New package: P<pv-0.4.9-20030219>
@@ .
______________________________________________________________________
The OpenPKG Project www.openpkg.org
CVS Repository Commit List [EMAIL PROTECTED]