More taint mode problems (please help)
mikej at rogers.com
Thu Jan 14 17:24:37 GMT 2010
On Wed, January 13, 2010 2:36 pm, Jules Field wrote:
> The File.pm module is used for opening files, not the "file" command. It
> could be loads of places.
> What TNEF-related options are you using, and can you send me a message
> that triggers it? Put the raw message queue files up on a website
> somewhere and mail me the URL to the address in the headers.
I believe the problem here is that the variable containing the filename
which is passed to File.pm is tainted.
More information about the MailScanner