Bug#304712: avaMail allows directory traversal in attachments (CAN-2005-1105)

2007-04-25 Thread Javier Serrano Polo
El dc 25 de 04 del 2007 a les 07:12 +0200, en/na Florian Weimer va escriure: It's from the GNU implementation against which this bug report was filed. I still don't know the origin. It may be from JavaMail 1.3.2 implementation.

Bug#304712: avaMail allows directory traversal in attachments (CAN-2005-1105)

2007-04-25 Thread Javier Serrano Polo
El dc 25 de 04 del 2007 a les 11:44 +0200, en/na Javier Serrano Polo va escriure: I still don't know the origin. It may be from JavaMail 1.3.2 implementation. Looking at section 7. VULNERABLE SOURCE CODE, it looks like the original submitter didn't check any documentation.

Bug#304712: avaMail allows directory traversal in attachments (CAN-2005-1105)

2007-04-24 Thread Florian Weimer
* Javier Serrano Polo: The JavaMail spec is clear enough about what should (must) do the implementation. As Chris already said, it returns the actual message content. Security isn't handled in this step. Any implementation altering this value doesn't follow the spec. Any application relying

Bug#304712: avaMail allows directory traversal in attachments (CAN-2005-1105)

2007-04-24 Thread Javier Serrano Polo
El dt 24 de 04 del 2007 a les 19:17 +0200, en/na Florian Weimer va escriure: I guess the documentation shoud be clarified: I don't know where that text came from (it's in a previous link, I know). From: http://java.sun.com/j2ee/1.4/docs/api/javax/mail/internet/MimeBodyPart.html#getFileName()

Bug#304712: avaMail allows directory traversal in attachments (CAN-2005-1105)

2007-04-24 Thread Florian Weimer
* Javier Serrano Polo: El dt 24 de 04 del 2007 a les 19:17 +0200, en/na Florian Weimer va escriure: I guess the documentation shoud be clarified: I don't know where that text came from (it's in a previous link, I know). From: It's from the GNU implementation against which this bug report