openbsd-ports/mail/majordomo/patches
dhartmei e97d74c80a Change default configuration options
which_access open -> closed
  who_access open -> closed
  max_which_hits 0 -> 1

Those would allow a spammer to harvest all subscriber addresses
if not changed by the list admin. Reported on

http://online.securityfocus.com/archive/1/310113/2003-02-03/2003-02-09/0

Don't restrict the which arguments as the article suggests, though,
because with which_access list and max_which_hits 1, there's no
reason to destroy a useful command.
2003-02-06 19:30:18 +00:00
..
patch-approve Majordomo port, by Daniel Hartmeier. 2000-05-22 16:33:43 +00:00
patch-archive2_pl ~= -> =~ ; sigh sigh 2000-05-24 14:35:41 +00:00
patch-archive_mh_pl ~= -> =~ ; sigh sigh 2000-05-24 14:35:41 +00:00
patch-bounce Majordomo port, by Daniel Hartmeier. 2000-05-22 16:33:43 +00:00
patch-bounce-remind ~= -> =~ ; sigh sigh 2000-05-24 14:35:41 +00:00
patch-config_parse_pl Change default configuration options 2003-02-06 19:30:18 +00:00
patch-config-test change the configuration file to /etc/majordomo/majordomo.cf and fix 2000-05-23 20:17:03 +00:00
patch-digest change the configuration file to /etc/majordomo/majordomo.cf and fix 2000-05-23 20:17:03 +00:00
patch-majordomo ~= -> =~ ; sigh sigh 2000-05-24 14:35:41 +00:00
patch-Makefile change the configuration file to /etc/majordomo/majordomo.cf and fix 2000-05-23 20:17:03 +00:00
patch-medit ~= -> =~ ; sigh sigh 2000-05-24 14:35:41 +00:00
patch-new-list ~= -> =~ ; sigh sigh 2000-05-24 14:35:41 +00:00
patch-request-answer ~= -> =~ ; sigh sigh 2000-05-24 14:35:41 +00:00
patch-resend change the configuration file to /etc/majordomo/majordomo.cf and fix 2000-05-23 20:17:03 +00:00
patch-sample_cf Change default configuration options 2003-02-06 19:30:18 +00:00
patch-sequencer ~= -> =~ ; sigh sigh 2000-05-24 14:35:41 +00:00
patch-wrapper_c change the configuration file to /etc/majordomo/majordomo.cf and fix 2000-05-23 20:17:03 +00:00