Re: [Mailman-Developers] Re: [Mailman-Users] security heads up - path traversal with 2.1.5

2005-02-15 Thread Tokio Kikuchi
Hi, Barry Warsaw wrote: > On Wed, 2005-02-09 at 17:00, Tokio Kikuchi wrote: > > >>I've tested with my 1.3.29 installation and verified apache PATH_INFO >>does convert '//' to '/'. Barry also wanted to clarify which apache >>version/installation (combination with mailman) is valnerable. Return

Re: [Mailman-Developers] Re: [Mailman-Users] security heads up - path traversal with 2.1.5

2005-02-14 Thread Brad Knowles
At 5:12 PM -0500 2005-02-14, Barry Warsaw wrote: In response to this issue, FAQ 1.27 has been updated Wow Brad, I was just about to change this to read [EMAIL PROTECTED] but you beat me to it by seconds. :) Mark had clued me in that someone had changed the security-related pages at www.list.o

Re: [Mailman-Developers] Re: [Mailman-Users] security heads up - path traversal with 2.1.5

2005-02-14 Thread Barry Warsaw
On Mon, 2005-02-14 at 10:23, Brad Knowles wrote: > In response to this issue, FAQ 1.27 has been updated Wow Brad, I was just about to change this to read [EMAIL PROTECTED] but you beat me to it by seconds. :) > , and the > mailman-users and mailman-developers mailing lists have likewise b

Re: [Mailman-Developers] Re: [Mailman-Users] security heads up - path traversal with 2.1.5

2005-02-14 Thread Barry Warsaw
On Wed, 2005-02-09 at 17:00, Tokio Kikuchi wrote: > I've tested with my 1.3.29 installation and verified apache PATH_INFO > does convert '//' to '/'. Barry also wanted to clarify which apache > version/installation (combination with mailman) is valnerable. Return > code of 200 doesn't mean suce