[Home]

Summary:ASTERISK-02640: [PATCH] vmail.cgi patch to work with newer realtime config db name, and fixes taint problems when forwarding voicemails
Reporter:zebble (zebble)Labels:
Date Opened:2004-10-20 11:18:56Date Closed:2008-01-15 15:12:19.000-0600
Priority:MajorRegression?No
Status:Closed/CompleteComponents:Core/General
Versions:Frequency of
Occurrence
Related
Issues:
Environment:Attachments:( 0) vmail.diff
Description:This patch updates vmail.cgi to work with the newer realtime configuration (uses voicemail table instead of users table).
This also fixes a taint problem when forwarding voicemails.  It basically "untaints" the path in the makedir command, as well as the filename/path in the open commands.

****** ADDITIONAL INFORMATION ******

Disclaimer is on file.
Comments:By: Olle Johansson (oej) 2004-10-20 13:36:31

Thank you for a proper report!
/Bug marshal oej

By: Mark Spencer (markster) 2004-10-31 21:06:18.000-0600

Fixed in CVS

By: Russell Bryant (russell) 2004-11-02 20:56:07.000-0600

not in 1.0

By: Digium Subversion (svnbot) 2008-01-15 15:12:19.000-0600

Repository: asterisk
Revision: 4140

U   trunk/contrib/scripts/vmail.cgi

------------------------------------------------------------------------
r4140 | markster | 2008-01-15 15:12:19 -0600 (Tue, 15 Jan 2008) | 2 lines

vmail.cgi updates (bug ASTERISK-2640)

------------------------------------------------------------------------

http://svn.digium.com/view/asterisk?view=rev&revision=4140