Bug 223648

Summary: squirrelmail ships with .orig files
Product: [Fedora] Fedora Reporter: Daniel Hokka Zakrisson <daniel>
Component: squirrelmailAssignee: Warren Togami <wtogami>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 6CC: wtogami
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: squirrelmail-1.4.8-5 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-01-29 17:23:51 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Patch to get rid of the files none

Description Daniel Hokka Zakrisson 2007-01-21 07:26:15 UTC
Description of problem:
squirrelmail ships with several .orig files resulting from offsets when applying
the patches:
$ rpm -qlp squirrelmail-1.4.8-3.fc6.noarch.rpm | grep .orig
/usr/share/squirrelmail/functions/i18n.php.orig
/usr/share/squirrelmail/functions/mime.php.orig
/usr/share/squirrelmail/src/compose.php.orig
/usr/share/squirrelmail/src/right_main.php.orig
/usr/share/squirrelmail/src/view_text.php.orig

This doesn't cause any problems, it just looks bad. The attached patch got rid
of them here.

Version-Release number of selected component (if applicable):
1.4.8-3.fc6

Comment 1 Daniel Hokka Zakrisson 2007-01-21 07:26:15 UTC
Created attachment 146078 [details]
Patch to get rid of the files

Comment 2 Daniel Hokka Zakrisson 2007-01-21 07:32:21 UTC
> This doesn't cause any problems, it just looks bad.

Just as I hit commit, I realized that these files can be used to exploit the
vulnerabilities the patches are meant to address.

Comment 3 Warren Togami 2007-01-22 05:01:58 UTC
Are you sure they can be?

Comment 4 Daniel Hokka Zakrisson 2007-01-22 05:59:37 UTC
I haven't tried exploiting it, but the files are accessible and do create the
expected output. Try accessing e.g. /webmail/src/right_main.php.orig.