Gentoo Archives: gentoo-dev

From: Fabian Groffen <grobian@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [News item review] Exim >=4.94 transports: tainted not permitted
Date: Thu, 06 May 2021 13:07:54
Message-Id: YJPqGGyqWnKgvVxq@gentoo.org
In Reply to: Re: [gentoo-dev] [News item review] Exim >=4.94 transports: tainted not permitted by "Andreas K. Huettel"
1 On 06-05-2021 15:01:33 +0200, Andreas K. Huettel wrote:
2 > > Unfortunately there is not much documentation on "tainted" data for
3 > > Exim[1], and to resolve this, non-official sources need to be used,
4 > > such as [2] and [3].
5 >
6 > This is a safety mechanism that is part of Perl (essentially a way of
7 > tracking data that is derived from "insecure" sources).
8 >
9 > So it probably would make sense to at least point towards that concept
10 > in Perl.
11
12 I think the concept is clear to most from the descriptions one can find.
13 The big problem however is the solution, how to fix one's configuration.
14
15 Luckily it seems people find their way to Exim's bugtracker to get help
16 there.
17
18 Thanks for the suggestion though,
19 Fabian
20
21
22 --
23 Fabian Groffen
24 Gentoo on a different level

Attachments

File name MIME type
signature.asc application/pgp-signature