From eb74e33c3ff041553af35293dc3cd3add5d5e8ce Mon Sep 17 00:00:00 2001 From: David Woodhouse Date: Tue, 29 Dec 2020 15:01:57 +0000 Subject: [PATCH] Use ${local_part_data} for local delivery lookups because ${local_part} is tainted --- master | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/master b/master index 97af95e..b98f2df 100644 --- a/master +++ b/master @@ -376,7 +376,7 @@ userforward: procmail: driver = accept check_local_user - require_files = ${local_part}:${home}/.procmailrc + require_files = ${local_part_data}:${home}/.procmailrc transport = procmail no_verify @@ -448,7 +448,7 @@ procmail: delivery_date_add envelope_to_add return_path_add - command = "/usr/bin/procmail -d ${local_part}" + command = "/usr/bin/procmail -d ${local_part_data}" user = $local_part initgroups check_string = "From " @@ -460,7 +460,7 @@ local_delivery: delivery_date_add envelope_to_add return_path_add - file = /var/spool/mail/${local_part} + file = /var/spool/mail/${local_part_data} group = mail mode = 0660 no_mode_fail_narrower -- 2.49.0