ANNOUNCE: MIME-Tools security patch

Henry C. Chorlian chorlian at CBR.MED.HARVARD.EDU
Fri Jun 7 16:31:53 IST 2002


Same error after updating patch:

patch -p0 < mime-tools-patch.txt
  Looks like a new-style context diff.
Malformed patch at line 286:
patch: Line must begin with '+ ', '  ', or '! '.

Sorry.  Appreciate your help!


On Friday, June 07, 2002 at 01:54:05 PM, MailScanner mailing list wrote:

> At 13:25 07/06/2002, you wrote:
> >When run I get the following:
> >
> >patch -p0 < mime-tools-patch.txt
> >   Looks like a new-style context diff.
> >Malformed patch at line 286:
> >patch: Line must begin with '+ ', '  ', or '! '.
> >
> >Not sure what this means?
>
> You need a newer version of "patch". Try http://www.sunfreeware.com/
>
> I must admit I ended up patching the 2 files on a Linux box (much better
> "patch") and then copying them over to the Solaris box :-)
>
> >On Friday, June 07, 2002 at 11:32:11 AM, MailScanner mailing list wrote:
> >
> > > A very nice person on the Bugtraq mailing list has found some potential
> > > security problems with the current stable release of the MIME-Tools module
> > > which is used by MailScanner. These are likely to be exploited fairly soon
> > > as the hackers all read Bugtraq too.
> > >
> > > A patch to correct these problems is attached to this message.
> > >
> > > You should find that the command
> > >          patch -p0 < mime-tools-patch.txt
> > > will install the patch, but it will probably ask you to locate the 2 files
> > > it needs to patch. Have a hunt round your Perl installation for the
> > > site_perl directory and take a look in there. If you can't find your
> > > site_perl directory anywhere, then run this perl script:
> > >          #!/usr/bin/perl
> > >          print join("\n", @INC);
> > > and the output of that will tell you where to look for it.
> > >
> > > Please don't ask me for more advice on using the patch command, there's a
> > > perfectly good man page about it and patch is very intelligent anyway, so
> > > you shouldn't have much problem.
> > >
> > > Jules.
> > >
> >
> >------------------------------------------
> >Henry C. Chorlian
> >Director of Information Technology
> >Center for Blood Research
> >800 Huntington Avenue
> >Boston, MA  02115-6303
> >
> >Harvard Medical School Affiliate
> >chorlian at cbr.med.harvard.edu
> >Voice:  (617) 278-3425
> >Fax:  (617) 278-3493
>
> --
> Julian Field                Teaching Systems Manager
> jkf at ecs.soton.ac.uk         Dept. of Electronics & Computer Science
> Tel. 023 8059 2817          University of Southampton
>                              Southampton SO17 1BJ
>
>

------------------------------------------
Henry C. Chorlian
Director of Information Technology
Center for Blood Research
800 Huntington Avenue
Boston, MA  02115-6303

Harvard Medical School Affiliate
chorlian at cbr.med.harvard.edu
Voice:  (617) 278-3425
Fax:  (617) 278-3493



More information about the MailScanner mailing list