From 662717cd020fecd9c1bb356ff0464b7c5e3830ec Mon Sep 17 00:00:00 2001 From: "jocuri%softhome.net" <> Date: Sun, 19 Oct 2003 15:32:46 +0000 Subject: [PATCH] Bug 220332: Insecure dependency in exec while running with -T switch at process_bug.cgi line 1267; r=justdave,gerv; a=justdave. --- process_bug.cgi | 2 ++ 1 file changed, 2 insertions(+) diff --git a/process_bug.cgi b/process_bug.cgi index aa8b668db7..205b3f3663 100755 --- a/process_bug.cgi +++ b/process_bug.cgi @@ -568,6 +568,8 @@ if (defined $::FORM{newcc} || defined $::FORM{removecc} || defined $::FORM{massc $cc_remove =~ s/[\s,]+/ /g; # Change all delimiters to a single space foreach my $person ( split(" ", $cc_remove) ) { my $pid = DBNameToIdAndCheck($person); + # if we got here, the DB has already verified the email + trick_taint($person); $cc_remove{$pid} = $person; } } -- 2.47.2