Re: [exim] Tainted arg 2 for mailman_transport transport com…

Page principale
Supprimer ce message
Répondre à ce message
Auteur: Kirill Miazine
Date:  
À: exim-users
Sujet: Re: [exim] Tainted arg 2 for mailman_transport transport command
• Thomas Krichel via Exim-users [2022-07-20 14:09]:
> Kirill Miazine via Exim-users writes
>
> > > What more to check?
> >
> > you could make a wrapper, e.g. like this:
> >
> > https://marc.info/?l=exim-users&m=165650068118956&w=2
>
> Thank you. I'm not au fait with this, so as a quick
> fix, I downgraded to 4.95, since I need to keep my service
> running. I suspect that
>
> https://www.exim.org/howto/mailman21.html
>
> needs changing to cope with 4.96. I would be happy to
> assist in this effort by testing.


IIRC Mailman has some facility to generate aliases file, which Exim
could be using. Mailman is able to generate those automatically, and
that should make the taint checking happy, as there won't be any unsafe
variables left.

Looking at https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/files/head:/Mailman/MTA
it seems you'd have to say that your MTA is Postfix.

-- 
    -- Kirill Miazine <km@???>