[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Maildir and Pine



On Thu, 6 Jan 2000, Robert Varga wrote:

> I always wondered what security vulnerabilities can a client program
> have...

Handling special characters in the content-type, I believe.  It is
possible, by setting IFS and escaped ';'s, to force execution of programs
in Pine's viewer.  Pine trying to be helpful by launching mime-viewers.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Sanjeev "Ghane" Gupta			Tel: +91(11) 6941831, 6945227
Eurolink Systems Ltd			Fax: +91(11) 6943732
New Delhi, India		      email: ghane@eurolink.stpn.soft.net
          Eurolink doesn't pay me to speak for it, so I don't
              Quid quid latine dictum sit, altum viditur


Reply to: