Re: Interim mitigation for CVE-2020-7247

2020-01-29 Thread gilles
January 29, 2020 12:19 PM, "Andreas Broecking" wrote: > Hi all, > > first of all, thanks Gilles for the heads-up and a fix on short notice. > > For people like me who relay on the portable version and for systems which > relay on built packages > as they lack the local development tools, a

Re: Interim mitigation for CVE-2020-7247

2020-01-29 Thread Andreas Broecking
Or rather filter exploit_check phase mail-from match mail-from regex { '.*\;.*\;.*’ } disconnect "550 no exploiting, kthx” to be more specific on the semicolons as delimiter of the command? (sorry, as I said. regex is my nemesis :)) Best regards Andreas > On 29. Jan 2020,

Interim mitigation for CVE-2020-7247

2020-01-29 Thread Andreas Broecking
Hi all, first of all, thanks Gilles for the heads-up and a fix on short notice. For people like me who relay on the portable version and for systems which relay on built packages as they lack the local development tools, a filter should help to mitigate the problem until a package could be