https://savannah.gnu.org/bugs/index.php?func=detailitem&item_id=15225

the short of it:
- email app uses "/" as the regex delimiter in the email attachemtn forwarding
- "/" is valid in a mime "boundary"
- a boundary with a / in it causes preg to think the regex is over

I don't know regex well enough to know how this could be exploited,
but it certainly prevents emails from being forwarded.  We could
change the delimiter to something not valid per the RFC, but then a
specialy crafted boundary could still cause phpgw problems.

what do you think?


_______________________________________________
Phpgroupware-developers mailing list
[email protected]
http://lists.gnu.org/mailman/listinfo/phpgroupware-developers

Reply via email to