can subscribe with CR+LF in email address

Bug #266107 reported by Thomas-ah-users
2
Affects Status Importance Assigned to Milestone
GNU Mailman
Fix Released
Medium
Unassigned

Bug Description

With Mailman 2.1.3 (didn't test with newer versions) it
is possible to subscribe with an email address which
ends with CR+LF.

A browser bug made it possible to enter this into the
single line entry field, but Mailman should check this.
A quick test shows that CR+LF is possible in the middle
of an email address, too, but of course this only works
when confirmation check is disabled.

Unsubscribing or changing the email address wasn't
possible, because there are checks against this strange
address. Only manually removing all dictionary entries
with 'withlist' helped.

[http://sourceforge.net/tracker/index.php?func=detail&aid=998609&group_id=103&atid=100103]

Revision history for this message
Tokio Kikuchi (tkikuchi) wrote :
Revision history for this message
Thomas-ah-users (thomas-ah-users) wrote :

The patch (already in CVS) helps, thanks.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.