Bug#268458: marked as done (libmime-lite-perl: $msg->send() should work in taint mode, ideally)
Debian Bug Tracking System
owner@bugs.debian.org
Thu, 02 Dec 2004 13:03:22 -0800
Your message dated Thu, 02 Dec 2004 15:48:22 -0500
with message-id <E1CZxsE-0001qC-00@newraff.debian.org>
and subject line Bug#268458: fixed in libmime-lite-perl 3.01-3
has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)
Debian bug tracking system administrator
(administrator, Debian Bugs database)
--------------------------------------
Received: (at submit) by bugs.debian.org; 27 Aug 2004 20:06:57 +0000
>From chops@demiurgestudios.com Fri Aug 27 13:06:56 2004
Return-path: <chops@demiurgestudios.com>
Received: from (qix.demiurgestudios.com) [12.151.131.245]
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1C0mzw-0003AX-00; Fri, 27 Aug 2004 13:06:56 -0700
Received: from [192.168.1.100] (helo=pogo.intelio.com)
by qix.demiurgestudios.com with esmtp (Exim 3.35 #1 (Debian))
id 1C0mzu-0006Xi-00; Fri, 27 Aug 2004 16:06:54 -0400
Received: by pogo.intelio.com (Postfix, from userid 501)
id 9D5FD32971; Fri, 27 Aug 2004 16:06:53 -0400 (EDT)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Andrew Moise <chops@demiurgestudios.com>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: libmime-lite-perl: $msg->send() should work in taint mode, ideally
X-Mailer: reportbug 2.64
Date: Fri, 27 Aug 2004 16:06:53 -0400
Message-Id: <20040827200653.9D5FD32971@pogo.intelio.com>
X-BadReturnPath: moise@pogo.internal.demiurgestudios.com rewritten as chops@demiurgestudios.com
using "From" header
Delivered-To: submit@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_25
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE
autolearn=no version=2.60-bugs.debian.org_2004_03_25
X-Spam-Level:
Package: libmime-lite-perl
Version: 2.117-5
Severity: wishlist
In a perfect world, calling $msg->send would be possible in taint mode, even
if the path were set insecurely (currently it says 'Insecure $ENV{PATH} while
running with -T switch at /usr/share/perl5/MIME/Lite.pm line 2550.').
$msg->send('sendmail') is accepted in taint mode right now, bizarrely enough,
but that's less portable to non-Unix systems.
-- System Information:
Debian Release: 3.1
APT prefers unstable
APT policy: (500, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.7+mppe
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8
Versions of packages libmime-lite-perl depends on:
ii perl 5.8.4-2 Larry Wall's Practical Extraction
-- no debconf information
---------------------------------------
Received: (at 268458-close) by bugs.debian.org; 2 Dec 2004 20:50:23 +0000
>From katie@ftp-master.debian.org Thu Dec 02 12:50:23 2004
Return-path: <katie@ftp-master.debian.org>
Received: from newraff.debian.org [208.185.25.31] (mail)
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1CZxuB-00051y-00; Thu, 02 Dec 2004 12:50:23 -0800
Received: from katie by newraff.debian.org with local (Exim 3.35 1 (Debian))
id 1CZxsE-0001qC-00; Thu, 02 Dec 2004 15:48:22 -0500
From: Gunnar Wolf <gwolf@debian.org>
To: 268458-close@bugs.debian.org
X-Katie: $Revision: 1.54 $
Subject: Bug#268458: fixed in libmime-lite-perl 3.01-3
Message-Id: <E1CZxsE-0001qC-00@newraff.debian.org>
Sender: Archive Administrator <katie@ftp-master.debian.org>
Date: Thu, 02 Dec 2004 15:48:22 -0500
Delivered-To: 268458-close@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_25
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER
autolearn=no version=2.60-bugs.debian.org_2004_03_25
X-Spam-Level:
Source: libmime-lite-perl
Source-Version: 3.01-3
We believe that the bug you reported is fixed in the latest version of
libmime-lite-perl, which is due to be installed in the Debian FTP archive:
libmime-lite-perl_3.01-3.diff.gz
to pool/main/libm/libmime-lite-perl/libmime-lite-perl_3.01-3.diff.gz
libmime-lite-perl_3.01-3.dsc
to pool/main/libm/libmime-lite-perl/libmime-lite-perl_3.01-3.dsc
libmime-lite-perl_3.01-3_all.deb
to pool/main/libm/libmime-lite-perl/libmime-lite-perl_3.01-3_all.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 268458@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Gunnar Wolf <gwolf@debian.org> (supplier of updated libmime-lite-perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Thu, 2 Dec 2004 13:42:08 -0600
Source: libmime-lite-perl
Binary: libmime-lite-perl
Architecture: source all
Version: 3.01-3
Distribution: unstable
Urgency: low
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: Gunnar Wolf <gwolf@debian.org>
Description:
libmime-lite-perl - Perl5 module for convenient generation of MIME messages
Closes: 268458
Changes:
libmime-lite-perl (3.01-3) unstable; urgency=low
.
* Set the path to a sane default (/bin:/usr/bin) so that MIME::Lite
will agree to send messages while running in Tainted mode (Closes:
#268458)
Files:
07c9aa7c60dc7e9cbea88c5bf0c3a8fc 691 perl optional libmime-lite-perl_3.01-3.dsc
5c0d1b280b068dc5a2dd53b03dc2c9cd 3788 perl optional libmime-lite-perl_3.01-3.diff.gz
e7dfd2dbec4992214f56fc941ea3f96b 65322 perl optional libmime-lite-perl_3.01-3_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
iD8DBQFBr3DG2A7zWou1J68RAhzSAJ92JKf8kJGxPUfN6u1zR+kfT135jQCgiwUo
7RpBOGz2Mrzv5CRJMejvPtw=
=yAZI
-----END PGP SIGNATURE-----