git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] avoid insecure use of mail in man page example

From
Jonathan Nieder <jrnieder@gmail.com>
Date
Oct 18, 2021, 00:55 UTC
Message-ID
<YWzF6deqfffBM7ub@gmail.com>
In-Reply-To
<YVOy0HLvManYQdGo@coredump.intra.peff.net>
Hi,
Jeff King wrote:
> On Tue, Sep 28, 2021 at 04:46:52PM -0700, Junio C Hamano wrote:
>>> On Tue, Sep 28, 2021 at 08:16:48AM -0400, Joey Hess wrote:
>>>> As recently seen in fail2ban's security hole (CVE-2021-32749),
>>>> piping user controlled input to mail is exploitable,
>>>> since a line starting with "~! foo" in the input will run command foo.
[...]
Show 17 quoted lines
>> It is not the primary focus for this documentation page to teach how
>> to send e-mails in the first place.  Instead of risking confused
>> users rightly complain with "my 'mail' does not understand the -E
>> option---what does this do?", I wonder if it is better to just change it to
>> 
>> 	git rev-list --pretty ...
>> -   fi |
>> -   mail -s ...    
>> +   fi >>/var/log/update.log
>> 
>> so that it illustrates what's available *out* *of* *us* to the
>> authors of the script, without having to teach them "mail" and other
>> things we are responsible for.
>
> Yeah, I'd agree that side-stepping the issue entirely is a good
> direction. Doing it right is probably best left to tools like
> git-multimail.

This makes sense to me. Joey, are you planning to send an updated version of the patch, or would you like us to take care of it?

Thanks, Jonathan

Previous: Jeff King
Message 5 of 5 in “avoid insecure use of mail in man page example”
  1. avoid insecure use of mail in man page exampleJoey Hess, Sep 28, 2021
  2. Jeff KingSep 28, 2021
  3. Junio C HamanoSep 28, 2021
  4. Jeff KingSep 29, 2021
  5. Jonathan NiederOct 18, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.