While testing this patch, it seems that there is still a condition where movemail wipes the mailbox (though it doesn't leak contents any more).
Here is an updated reproducer that tests for the conditions... ** Attachment added: "CVE-2010-0825.sh" http://launchpadlibrarian.net/41879562/CVE-2010-0825.sh -- Emacs movemail race condition https://bugs.launchpad.net/bugs/531569 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
