Hi Andrew,
One of my users has found and reported to me another issue with
regards to reading / listing private messages. While the fix in commit [942e85] works for local, private echos, it does not take into account
the possibillity of two users having the same name (e.g. "Tom Smith")
but different AKAs. Since the fix in [942e85] does not check the From
/ To addresses this may lead to the possibility of a user"Tom
Smith@1:2/3" reading and being able to list messages for "Tom Smith@3:4/5".
I've already fixed the if (..) statments in mail.c (lines 1116, 1258
and 1909) and will provide a proper pull request in the next few days.
I just wanted to inform you that there is still a security issue and
that there is work being done to fix it.
This check should only be applied in NetMail areas. EchoMail areas, by definition, do not specify a destination address, but only a to name.
| Sysop: | digital man |
|---|---|
| Location: | Riverside County, California |
| Users: | 1,166 |
| Nodes: | 17 (0 / 17) |
| Uptime: | 428:40:28 |
| Calls: | 509,423 |
| Calls today: | 9 |
| Files: | 264,742 |
| D/L today: |
17,437 files (3,506M bytes) |
| Messages: | 470,044 |
| Posted today: | 8 |