RE: [Exim] Exim 4.34 environment variable patch

Top Page
Delete this message
Reply to this message
Author: Eli
Date:  
To: 'Nico Erfurth', 'Hagen Paul Pfeifer'
CC: 'Exim-Users \(E-mail\)'
Subject: RE: [Exim] Exim 4.34 environment variable patch
Nico Erfurth wrote:
> Hagen Paul Pfeifer wrote:
>
>> I think there is no wise exigence for this patch except for debuging
>> purpose, maybe.
>>
>> How many environment variable do you want to set to work effective?
>> One, two, ...? More is even error-prone and complex. I think there
>> exists better ways to communicate with exim.
>
> Also users could set environment variables and so influence the way
> exim works. *shudder*


That would be a *smack* for the person who configured Exim with such a
security "issue". My use does nothing more than log the information in the
email for tracking purposes. If you want to take action based on something
in an environment, you should first make sure that you can trust that
environment - if you can't, don't do it (this goes for other stuff in Exim
too :P).

> A better way would be to use a startup-script that sets macros,
> depending on environment variables, via -D.


Only better if the other way has a problem. I'm just handing people the gun
- it's up to them to shoot themselves or not :)

Eli.