Bug 223648 - squirrelmail ships with .orig files
Summary: squirrelmail ships with .orig files
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: squirrelmail
Version: 6
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Warren Togami
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-01-21 07:26 UTC by Daniel Hokka Zakrisson
Modified: 2007-11-30 22:11 UTC (History)
1 user (show)

Fixed In Version: squirrelmail-1.4.8-5
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2007-01-29 17:23:51 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
Patch to get rid of the files (614 bytes, patch)
2007-01-21 07:26 UTC, Daniel Hokka Zakrisson
no flags Details | Diff

Description Daniel Hokka Zakrisson 2007-01-21 07:26:15 UTC
Description of problem:
squirrelmail ships with several .orig files resulting from offsets when applying
the patches:
$ rpm -qlp squirrelmail-1.4.8-3.fc6.noarch.rpm | grep .orig
/usr/share/squirrelmail/functions/i18n.php.orig
/usr/share/squirrelmail/functions/mime.php.orig
/usr/share/squirrelmail/src/compose.php.orig
/usr/share/squirrelmail/src/right_main.php.orig
/usr/share/squirrelmail/src/view_text.php.orig

This doesn't cause any problems, it just looks bad. The attached patch got rid
of them here.

Version-Release number of selected component (if applicable):
1.4.8-3.fc6

Comment 1 Daniel Hokka Zakrisson 2007-01-21 07:26:15 UTC
Created attachment 146078 [details]
Patch to get rid of the files

Comment 2 Daniel Hokka Zakrisson 2007-01-21 07:32:21 UTC
> This doesn't cause any problems, it just looks bad.

Just as I hit commit, I realized that these files can be used to exploit the
vulnerabilities the patches are meant to address.

Comment 3 Warren Togami 2007-01-22 05:01:58 UTC
Are you sure they can be?

Comment 4 Daniel Hokka Zakrisson 2007-01-22 05:59:37 UTC
I haven't tried exploiting it, but the files are accessible and do create the
expected output. Try accessing e.g. /webmail/src/right_main.php.orig.


Note You need to log in before you can comment on or make changes to this bug.