Re: Pine 4.33 (at least) URL handler allows embedded commands.

From: Roman Drahtmueller (draht@suse.de)
Date: 01/07/02


Date: Mon, 7 Jan 2002 14:01:05 +0100 (MET)
From: Roman Drahtmueller <draht@suse.de>
To: bugtraq@securityfocus.com



> > Problem: URL handler allows embedded commands.
> > May allow email viruses of the Outlook kind.
>
> > http://address/'&/some/program${IFS}with${IFS}arguments&'
>
> Isn't that old news? http://www.securityfocus.com/bid/810
>
> I *can* be wrong, but it looks like it is the same problem...

SuSE pine packages contain a patch that makes pine use environment
variables to pass on the URL to the viewer. The patch is attached - I'm
not sure who made it, but it looks like from Olaf Kirch.

Roman.

-- 
 -                                                                      -
| Roman Drahtmüller      <draht@suse.de> // "You don't need eyes to see, |
  SuSE GmbH - Security           Phone: //             you need vision!"
| Nürnberg, Germany     +49-911-740530 //           Maxi Jazz, Faithless |
 -                                                                      -




Relevant Pages

  • Re: Announcing a VentureForth plugins experiment.
    ... the VentureForth compiler. ... announcement is news to them as much as it is news to all of you. ... The first is really a "patch". ... There are external memory concepts in the SEAforth design, ...
    (comp.lang.forth)
  • Re: Problem with inotify
    ... > The good news is that the hang is gone. ... the oops and below is the resulting patch. ... send the line "unsubscribe linux-kernel" in ...
    (Linux-Kernel)
  • Re: Any news... this just in
    ... But not good news. ... From the tech support contact I've ... "The patch has been delayed due to technical ... >>Microsoft Office and Microsoft Office related News ...
    (microsoft.public.outlook.general)
  • Re: Question about host, gethostbyname and getaddress
    ... I submitted a patch last night that changes the way gethostbyname/gethostbyaddr ... in the underlying OS and combine the output of them into the results you see. ... So, the bad news is once I fixed the error and tested with ruby 1.8, I'm ...
    (comp.lang.ruby)
  • Real-life (almost) dynamic range test.
    ... Good news 1: Yow! ... This thing has FIVE full stops of range over medium gray. ... Each step is 1/3 of a stop, so the overexposed image has the "M" patch at ... Zone I is patch "10" in the underexposed image, ...
    (rec.photo.digital)

Quantcast