[Mailman-Developers] Re: [Mailman-Users] mailman loops because of & in an address

J C Lawrence claw@kanga.nu
Tue, 23 Apr 2002 11:23:50 -0700


On Tue, 23 Apr 2002 14:49:37 +0200 (CEST) 
Antenna Support <support@antenna.nl> wrote:

> Dear people, We just experienced a loop: a message was sent many times
> because it wasn't deleted in the /home/mailman/qfiles directory The
> error mailed was:

> /usr/bin/python -S /home/mailman/cron/qrunner

> sh: c.lovell@xtra.co.nz: command not found c... User unknown

> It appeared that there was an address added to the list:
> m&c.lovell@xtra.co.nz

> The loop could only be stopped by removing the .msg and .db file in
> the qfiles directory. I also removed this address from the
> subscribers.

Aiiieee!

We should really sanitise inbound email addresses.  "&" is not a legal
char in a LHS.

-- 
J C Lawrence                
---------(*)                Satan, oscillate my metallic sonatas. 
claw@kanga.nu               He lived as a devil, eh?		  
http://www.kanga.nu/~claw/  Evil is a name of a foeman, as I live.