On Thu, May 5, 2011 at 5:35 PM, C. Bensend <benny@xxxxxxxxxxxxxxx> wrote: > > Hey folks, > > I identified four spam messages today that seem to send the > SquirrelMail interface into an infinite loop. > > The stats: > > OpenBSD 4.8-CURRENT snapshot from Aug 2010 > PHP 5.2.13 > SquirrelMail 1.4.21 > Dovecot 1.2.13 > > When any of these messages was in the list of messages to display, > the SquirrelMail web interface would show "Transferring data from > hostname..." (in Mozilla Firefox 3.6.17) and never complete drawing > the page. Checking the same mailbox with Mutt worked fine, and using > that to determine which message was causing the issue, I could > manually move the Maildir file out of the way. Once that was done, > the SquirrelMail interface could be refreshed and would eventually > recover. > > I have copies of the four messages, but I'm not going to post them > to the public in case there's an exploit being attempted. SquirrelMail > devs, please feel free to email me directly and I'll pass them along. Before proceeding, try a snapshot of version 1.4.22 -- Paul Lesniewski SquirrelMail Team Please support Open Source Software by donating to SquirrelMail! http://squirrelmail.org/donate_paul_lesniewski.php ------------------------------------------------------------------------------ WhatsUp Gold - Download Free Network Management Software The most intuitive, comprehensive, and cost-effective network management toolset available today. Delivers lowest initial acquisition cost and overall TCO of any competing solution. http://p.sf.net/sfu/whatsupgold-sd ----- squirrelmail-users mailing list Posting guidelines: http://squirrelmail.org/postingguidelines List address: squirrelmail-users@xxxxxxxxxxxxxxxxxxxxx List archives: http://news.gmane.org/gmane.mail.squirrelmail.user List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-users