Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 …

Top Page
Delete this message
Reply to this message
Author: Victor Ustugov
Date:  
To: Heiko Schlittermann via Exim-users
Subject: Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)
Heiko Schlittermann via Exim-users wrote on 05.05.2021 01:39:
> Jeremy Harris via Exim-users <exim-users@???> (Mi 05 Mai 2021 00:11:59 CEST):
>> Having made me go and look... that is what I did, in b8514d1960
>> (which is since 4.94). A comma-sep option "file=/foo" after
>> the word "sqlite".
>
> Yes, that's what I found. But I can't see this neither in 4.94, or
> 4.94+fixes.
>
> @Victor: Yes, the commit *can* be backported, but first I'd like to
> understand how this syntax worked for Odhiambo with 4.94.


It's depend on now Odhiambo built exim.


> And I do not want to drop the support for queries do different SQLite
> databases, but again - I'd like to understand why Odhiambo sees this
> working with 4.94.


> I'd just refuse to create a bloated 4.94+fixes, instead of releasing
> 4.95 as soon as possible.


Yesterday I build exim 4.94.2 with adapted code from Jeremy's commit.
It works as expected on FreeBSD (exim 4.94.2 from ports with my patches)
and Ubuntu (exim 4.94.2-1 built from Debian deb-src with my patches).


@Odhiambo: try this patch.

https://mta.org.ua/exim-4.94-conf/patches/exim-4.94%2Bfixes-fix-sqlite-tainted-filename/patch-src__exim-4.94%2Bfixes-fix-sqlite-tainted-filename.patch

This is minimalistic variant of Jeremy's code adapted for exim
4.94+fixes and exim 4.94.2


-- 
Best wishes
Victor Ustugov        mailto:victor@corvax.kiev.ua
Skype ID: corvax_nb   JID: victor@???
public GnuPG/PGP key: https://victor.corvax.kiev.ua/corvax.asc