Re: [Exim] [Security-l] lil' exim format bug (fwd)

Top Page
Delete this message
Reply to this message
Author: Tabor J. Wells
Date:  
To: Tamas TEVESZ
CC: exim-users
Subject: Re: [Exim] [Security-l] lil' exim format bug (fwd)
On Thu, Jun 07, 2001 at 05:05:23PM +0200,
Tamas TEVESZ <ice@???> is thought to have said:

> On Thu, 7 Jun 2001, Tabor J. Wells wrote:
>
> > I'm unable to get my 3.22 systems on Solaris 2.6 x86 and 8 on Sparc to
> > exhibit this behavior, with the options Megyer stated were necessary. I
> > wonder if it's OS specific.
>
> actually...
>
> exim 3.22 orig source, disabled eximon in makefile, make, added
> "split_spool_directory=/tmp" and "check_headers_syntax=true" to the
> default configure,
>
> tamas@devsoc2:~/exim/exim-3.22$ ./build-SunOS5-5.8-sparc/exim -C
> src/configure.default -bS
> mail from: ice@???
> rcpt to: tamas
> data
> From:@@%p%p%p%p%p%p%p%p%p%p
> .
> 2001-06-07 16:55:04 rejected from <tamas@devsoc2>: syntax error in
> 'From' header: domain missing or malformed: failing address is:
> @@%p%p%p%p%p%p%p%p%p%p
> 550 Syntax error in 'From' header: domain missing or malformed:
> failing address is: @@19e2ea0ffbef2b8a4c40a46280000


I can now replicate this. Sort of. I have no idea what I was doing
differently yesterday. The behavior is a bit different for me, though. I
don't get the logged info above, but I do get a segfault and a -D file in
my spool which contains about 25k of data including random bits of my
configure file, /etc/hosts, etc.

Thanks,

Tabor

-- 
--------------------------------------------------------------------
Tabor J. Wells                                     twells@???
Fsck It!                 Just another victim of the ambient morality