Bug#301236: Attachment paths (Debian bug 301236)

2006-03-23 Thread Justin Pryzby
On Fri, Mar 24, 2006 at 02:30:21AM +0100, Adeodato Sim?? wrote: > * Justin Pryzby [Thu, 23 Mar 2006 19:18:25 -0500]: > > > Adeodato, I noticed that the mutt build is a bit noisy while applying > > patches, > > http://buildd.debian.org/fetch.php?&pkg=mutt&ver=1.5.11%2Bcvs20060126-2&arch=m68k&stamp=

Bug#301236: Attachment paths (Debian bug 301236)

2006-03-23 Thread Adeodato Simó
* Justin Pryzby [Thu, 23 Mar 2006 19:18:25 -0500]: > Adeodato, I noticed that the mutt build is a bit noisy while applying > patches, > http://buildd.debian.org/fetch.php?&pkg=mutt&ver=1.5.11%2Bcvs20060126-2&arch=m68k&stamp=1141353835&file=log&as=raw Is this bad? -- Adeodato Simó

Bug#301236: Attachment paths (Debian bug 301236)

2006-03-23 Thread Justin Pryzby
tag 301236 patch thanks On Thu, Mar 23, 2006 at 10:34:24PM +, Paul Walker wrote: > Hi all, > > I hadn't noticed this one before. mutt CVS does indeed allow attachments to > have (and keep) arbitrary paths, which can't be good. Okay, you have to be > not paying attention in order to overwrite

Bug#301236: Attachment paths (Debian bug 301236)

2006-03-23 Thread Paul Walker
Hi all, I hadn't noticed this one before. mutt CVS does indeed allow attachments to have (and keep) arbitrary paths, which can't be good. Okay, you have to be not paying attention in order to overwrite files, but why give people the chance? Please try the attached patch, which sanitises the filen