components/procmail/patches/06.CVE-2014-3618.patch
author John Beck <John.Beck@Oracle.COM>
Wed, 18 Nov 2015 12:45:08 -0800
changeset 5106 7da49475ad49
parent 2067 e8c3cd17d19f
permissions -rw-r--r--
22227841 SUNWpyyaml26 needs to be obsoleted

This patch comes from upstream:

http://seclists.org/oss-sec/2014/q3/495

We presume it will be part of a future release of procmail.

--- procmail-3.22/src/formisc.c.~2~	2014-09-04 08:56:27.832599147 -0700
+++ procmail-3.22/src/formisc.c	2014-09-04 08:56:54.543558430 -0700
@@ -84,12 +84,11 @@
 	case '"':*target++=delim='"';start++;
       }
      ;{ int i;
-	do
+	while(*start)
 	   if((i= *target++= *start++)==delim)	 /* corresponding delimiter? */
 	      break;
 	   else if(i=='\\'&&*start)		    /* skip quoted character */
 	      *target++= *start++;
-	while(*start);						/* anything? */
       }
      hitspc=2;
    }