Re: Disable escapes to prevent command-injection attacks

"Sergey Poznyakoff" <[email protected]> Wed, 06 Oct 2021 21:45:08 +0200
Newsgroups gmane.comp.gnu.mailutils.bugs
Organization GNU.org.ua
Message-ID <[email protected]>
Quinn Comendant <[email protected]> ha escrit:

> I recently learned of a vulnerability where an arbitrary command can
> be executed by root if the body of an email passed to `mail` contains
> unsanitized ~! or ~| escapes.

This has been fixed on July 19 (commit 4befcfd015).  The fix is included
in version 3.13.  Please, upgrade.

Regards,
Sergey