Hi guys,

I think I've isolated and I found a workaround for the the problem, of
which I can repeatedly reproduce now.

If two users access their mail from same browser even logging out, their
session data gets mixed. However if the user access from another computer
it's again ok. The problem shows up if the user changes anything in their
prefs. Then the problem is persisted, written to disk.

In my setup SuSE 7.3 php 4.0.4 some damn idiot (probably me..ummm definetly
me) turned on the register globals parameter in php.ini. Actually this was
for some other application to work. After having the other application non
global friendly now it works ok. No user sessions are mixing up. This is
valid for all the versions including 1.4.x on this specific setup.

It was a serious flaw because people were getting other's mails because of
whatis (over)written as reply-to address in their prefs.

I hope this gives a hint to developers. After turning of register globals
it didn't happen as far as I know, but still watching closely.

Thanks a lot for your prompt responses.

Regards,
Oyku


>> Hi,
>>
>> I'm facing a very nasty problem lately. Some of my users started
>> reporting that they were receiving mails sent by other people. Here's
>> the scenario user A send and email to user B and user C gets the
>> reply.
>
> It is a known problem... I am working on fixing it again... Just make
> sure they don't login from the same browser... or logout first.
>
> --
> Jon Angliss
> ([EMAIL PROTECTED])
>
>
>
> -------------------------------------------------------
> This sf.net email is sponsored by:ThinkGeek
> Welcome to geek heaven.
> http://thinkgeek.com/sf
> --
> squirrelmail-users mailing list
> List Address: [EMAIL PROTECTED]
> List Archives:
> http://sourceforge.net/mailarchive/forum.php?forum_id=2995 List Info:
> https://lists.sourceforge.net/lists/listinfo/squirrelmail-users





-------------------------------------------------------
This SF.net email is sponsored by: Etnus, makers of TotalView, The debugger 
for complex code. Debugging C/C++ programs can leave you feeling lost and 
disoriented. TotalView can help you find your way. Available on major UNIX 
and Linux platforms. Try it free. www.etnus.com
--
squirrelmail-users mailing list
List Address: [EMAIL PROTECTED]
List Archives:  http://sourceforge.net/mailarchive/forum.php?forum_id=2995
List Info: https://lists.sourceforge.net/lists/listinfo/squirrelmail-users

Reply via email to