git-svn-id: https://svn.code.sf.net/p/squirrelmail/code/trunk/squirrelmail@13675
7612ce4b-ef26-0410-bec9-
ea0150e637f0
- Fixed the lack of sanitizing of contrib/decrypt_headers.php input;
also includes general cleanup of that page (Thanks to Niels Teusink).
[also CVE-2009-1578]
+ - Fixed unsanitized shell command in example IMAP username mapping
+ function (map_yp_alias) (Thanks to Niels Teusink). [CVE-2009-1579]
Version 1.5.1 (branched on 2006-02-12)
--------------------------------------
* @since 1.3.0
*/
function map_yp_alias($username) {
- $yp = `ypmatch $username aliases`;
+ $yp = `ypmatch ' . escapeshellarg($username) . ' aliases`;
return chop(substr($yp, strlen($username)+1));
}