Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 …

Top Page
Delete this message
Reply to this message
Author: Victor Ustugov
Date:  
To: Heiko Schlittermann via Exim-users
Subject: Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)
Heiko Schlittermann via Exim-users wrote on 05.05.2021 14:57:
> Victor Ustugov via Exim-users <exim-users@???> (Mi 05 Mai 2021 13:21:55 CEST):
>>> I'd just refuse to create a bloated 4.94+fixes, instead of releasing
>>> 4.95 as soon as possible.
>>
>> Yesterday I built exim 4.94.2 with adapted code from Jeremy's commit.
>> It works as expected on FreeBSD (exim 4.94.2 from ports with my patches)
>> and Ubuntu (exim 4.94.2-1 built from Debian deb-src with my patches).
>
> What did you do?


I built exim 4.94.2 with patch
https://mta.org.ua/exim-4.94-conf/patches/exim-4.94%2Bfixes-fix-sqlite-tainted-filename/patch-src__exim-4.94%2Bfixes-fix-sqlite-tainted-filename.patch

As I remember patch for exim 4.94 based on:

https://git.exim.org/exim.git/patch/44644c2e404a3ea0191db0b0458e86924fb240bb
https://git.exim.org/exim.git/patch/4a7dca52352d0976f200b89a50825433b7551554
https://git.exim.org/exim.git/patch/b8514d1960e259d49ab2c84c89eba52ab993da3f

Later I ported patch for exim 4.94+fixes.


# exim -be '${lookup sqlite,file=/var/spool/exim/db/access.db{SELECT
sender FROM awl WHERE sender="${quote_sqlite:exim-users@???}";}}'
exim-users@???


> I just cherry-picked the mentioned commit
> 4a7dca52352d0976f200b89a50825433b7551554
>
> But the error didn't disappear. I'll check in more detail now.
>
>



-- 
Best wishes
Victor Ustugov        mailto:victor@corvax.kiev.ua
Skype ID: corvax_nb   JID: victor@???
public GnuPG/PGP key: https://victor.corvax.kiev.ua/corvax.asc