https://bugs.exim.org/show_bug.cgi?id=2727
Bug ID: 2727
Summary: Failure to expand due to taint in 4.94.2
Product: Exim
Version: 4.94
Hardware: x86
OS: All
Status: NEW
Severity: bug
Priority: medium
Component: String expansion
Assignee: unallocated@???
Reporter: martynas@???
CC: exim-dev@???
With 4.94.2 we get the following (attaching comparison of how it worked in
4.94):
18:23:17 1707974 --------> virtual_aliases router <--------
18:23:17 1707974 local_part=asdads domain=domain.com
18:23:17 1707974 calling virtual_aliases router
18:23:17 1707974 rda_interpret (string): '${if
exists{/etc/virtual/$domain/aliases}{${lookup{$local_part}lsearch*{/etc/virtual/$domain/aliases}}}}'
18:23:17 1707974 âconsidering: ${if
exists{/etc/virtual/$domain/aliases}{${lookup{$local_part}lsearch*{/etc/virtual/$domain/aliases}}}}
18:23:17 1707974 âconsidering:
/etc/virtual/$domain/aliases}{${lookup{$local_part}lsearch*{/etc/virtual/$domain/aliases}}}}
18:23:17 1707974 âââexpanding: /etc/virtual/$domain/aliases
18:23:17 1707974 â°âââââresult: /etc/virtual/domain.com/aliases
18:23:17 1707974 â°ââ(tainted)
18:23:17 1707974 âââcondition: exists{/etc/virtual/$domain/aliases}
18:23:17 1707974 ââââââresult: true
18:23:17 1707974 âconsidering:
${lookup{$local_part}lsearch*{/etc/virtual/$domain/aliases}}}}
18:23:17 1707974 âconsidering:
$local_part}lsearch*{/etc/virtual/$domain/aliases}}}}
18:23:17 1707974 âââexpanding: $local_part
18:23:17 1707974 â°âââââresult: asdads
18:23:17 1707974 â°ââ(tainted)
18:23:17 1707974 âconsidering: /etc/virtual/$domain/aliases}}}}
18:23:17 1707974 âââexpanding: /etc/virtual/$domain/aliases
18:23:17 1707974 â°âââââresult: /etc/virtual/domain.com/aliases
18:23:17 1707974 â°ââ(tainted)
18:23:17 1707974 LOG: MAIN PANIC
18:23:17 1707974 Tainted filename for search:
'/etc/virtual/domain.com/aliases'
18:23:17 1707974 âfailed to expand:
${lookup{$local_part}lsearch*{/etc/virtual/$domain/aliases}}}}
18:23:17 1707974 â°âââerror message: NULL
18:23:17 1707974 âfailed to expand: ${if
exists{/etc/virtual/$domain/aliases}{${lookup{$local_part}lsearch*{/etc/virtual/$domain/aliases}}}}
18:23:17 1707974 â°âââerror message: NULL
18:23:17 1707974 virtual_aliases router: defer for asdads@???
18:23:17 1707974 message: failed to expand "${if
exists{/etc/virtual/$domain/aliases}{${lookup{$local_part}lsearch*{/etc/virtual/$domain/aliases}}}}":
NULL
18:23:17 1707974 ----------- end verify ------------
18:23:17 1707974 deny: condition test deferred in ACL "acl_check_recipient"
18:23:17 1707974 SMTP>> 451 Temporary local problem - please try later
18:23:17 1707974 LOG: MAIN REJECT
18:23:17 1707974 H=localhost (centos8.martynas.it) [::1]
F=<asdasd1@???> temporarily rejected RCPT asdads@???: failed to
expand "${if
exists{/etc/virtual/$domain/aliases}{${lookup{$local_part}lsearch*{/etc/virtual/$domain/aliases}}}}":
NULL
4.94:
18:28:50 1713224 --------> virtual_aliases router <--------
18:28:50 1713224 local_part=asdasd1 domain=domain.com
18:28:50 1713224 checking domains
18:28:50 1713224 search_open: lsearch "/etc/virtual/domainowners"
18:28:50 1713224 cached open
18:28:50 1713224 search_find: file="/etc/virtual/domainowners"
18:28:50 1713224 key="domain.com" partial=-1 affix=NULL starflags=0
opts="ret=key"
18:28:50 1713224 LRU list:
18:28:50 1713224 6/etc/virtual/domainowners
18:28:50 1713224 6/etc/virtual/domain.com/aliases
18:28:50 1713224 6/etc/virtual/domain.com/passwd
18:28:50 1713224 6/etc/virtual/domain.com/autoresponder.conf
18:28:50 1713224 6/etc/virtual/domain.com/majordomo/list.aliases
18:28:50 1713224 6/etc/virtual/domains
18:28:50 1713224 7/etc/virtual/blacklist_domains
18:28:50 1713224 7/etc/virtual/bad_sender_hosts
18:28:50 1713224 7/etc/virtual/blacklist_senders
18:28:50 1713224 7/etc/virtual/skip_rbl_domains
18:28:50 1713224 6/etc/virtual/use_rbl_domains
18:28:50 1713224 6/etc/passwd
18:28:50 1713224 7/etc/virtual/whitelist_senders
18:28:50 1713224 7/etc/virtual/whitelist_hosts
18:28:50 1713224 7/etc/virtual/whitelist_domains
18:28:50 1713224 5/etc/virtual/helo_data
18:28:50 1713224 End
18:28:50 1713224 internal_search_find: file="/etc/virtual/domainowners"
18:28:50 1713224 type=lsearch key="domain.com" opts="ret=key"
18:28:50 1713224 cached data used for lookup of domain.com
18:28:50 1713224 in /etc/virtual/domainowners
18:28:50 1713224 lookup yielded: bogdan8
18:28:50 1713224 lookup ret=key: domain.com
18:28:50 1713224 domain.com in "lsearch,ret=key;/etc/virtual/domainowners"? yes
(matched "lsearch,ret=key;/etc/virtual/domainowners")
18:28:50 1713224 calling virtual_aliases router
18:28:50 1713224 rda_interpret (string): '${if
exists{/etc/virtual/$domain_data/aliases}{${lookup{$local_part}lsearch*{/etc/virtual/$domain_data/aliases}}}}'
18:28:50 1713224 âconsidering: ${if
exists{/etc/virtual/$domain_data/aliases}{${lookup{$local_part}lsearch*{/etc/virtual/$domain_data/aliases}}}}
18:28:50 1713224 âconsidering:
/etc/virtual/$domain_data/aliases}{${lookup{$local_part}lsearch*{/etc/virtual/$domain_data/aliases}}}}
18:28:50 1713224 âââexpanding: /etc/virtual/$domain_data/aliases
18:28:50 1713224 â°âââââresult: /etc/virtual/domain.com/aliases
18:28:50 1713224 âââcondition: exists{/etc/virtual/$domain_data/aliases}
18:28:50 1713224 ââââââresult: true
18:28:50 1713224 âconsidering:
${lookup{$local_part}lsearch*{/etc/virtual/$domain_data/aliases}}}}
18:28:50 1713224 âconsidering:
$local_part}lsearch*{/etc/virtual/$domain_data/aliases}}}}
18:28:50 1713224 âââexpanding: $local_part
18:28:50 1713224 â°âââââresult: asdasd1
18:28:50 1713224 â°ââ(tainted)
18:28:50 1713224 âconsidering: /etc/virtual/$domain_data/aliases}}}}
18:28:50 1713224 âââexpanding: /etc/virtual/$domain_data/aliases
18:28:50 1713224 â°âââââresult: /etc/virtual/domain.com/aliases
18:28:50 1713224 search_open: lsearch "/etc/virtual/domain.com/aliases"
18:28:50 1713224 cached open
18:28:50 1713224 search_find: file="/etc/virtual/domain.com/aliases"
18:28:50 1713224 key="asdasd1" partial=-1 affix=NULL starflags=1 opts=NULL
18:28:50 1713224 LRU list:
18:28:50 1713224 6/etc/virtual/domain.com/aliases
18:28:50 1713224 6/etc/virtual/domainowners
18:28:50 1713224 6/etc/virtual/domain.com/passwd
18:28:50 1713224 6/etc/virtual/domain.com/autoresponder.conf
18:28:50 1713224 6/etc/virtual/domain.com/majordomo/list.aliases
18:28:50 1713224 6/etc/virtual/domains
18:28:50 1713224 7/etc/virtual/blacklist_domains
18:28:50 1713224 7/etc/virtual/bad_sender_hosts
18:28:50 1713224 7/etc/virtual/blacklist_senders
18:28:50 1713224 7/etc/virtual/skip_rbl_domains
18:28:50 1713224 6/etc/virtual/use_rbl_domains
18:28:50 1713224 6/etc/passwd
18:28:50 1713224 7/etc/virtual/whitelist_senders
18:28:50 1713224 7/etc/virtual/whitelist_hosts
18:28:50 1713224 7/etc/virtual/whitelist_domains
18:28:50 1713224 5/etc/virtual/helo_data
18:28:50 1713224 End
18:28:50 1713224 internal_search_find: file="/etc/virtual/domain.com/aliases"
18:28:50 1713224 type=lsearch key="asdasd1" opts=NULL
18:28:50 1713224 cached data used for lookup of asdasd1
18:28:50 1713224 in /etc/virtual/domain.com/aliases
18:28:50 1713224 lookup yielded: bogdan@???
18:28:50 1713224 âââexpanding:
${lookup{$local_part}lsearch*{/etc/virtual/$domain_data/aliases}}
18:28:50 1713224 â°âââââresult: bogdan@???
18:28:50 1713224 âââexpanding: ${if
exists{/etc/virtual/$domain_data/aliases}{${lookup{$local_part}lsearch*{/etc/virtual/$domain_data/aliases}}}}
18:28:50 1713224 â°âââââresult: bogdan@???
18:28:50 1713224 expanded: 'bogdan@???'
18:28:50 1713224 file is not a filter file
18:28:50 1713224 parse_forward_list: bogdan@???
18:28:50 1713224 extract item: bogdan@???
18:28:50 1713224 virtual_aliases router generated bogdan@???
18:28:50 1713224 errors_to=NULL transport=NULL
18:28:50 1713224 uid=unset gid=unset home=NULL
18:28:50 1713224 routed by virtual_aliases router
18:28:50 1713224 envelope to: asdasd1@???
18:28:50 1713224 transport: <none>
18:28:50 1713224 >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
18:28:50 1713224 Considering bogdan@???
18:28:50 1713224 >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
18:28:50 1713224 routing bogdan@???
...
Did something change there? I don't see any changelog entries for hardened
taints.
--
You are receiving this mail because:
You are on the CC list for the bug.