From: Tim Seaver <>
To: phage
Date: Mon 13:49:11 14/11/1988 EST
Subject: rmail
>Date: Fri, 11 Nov 88 17:51:58 PST
>From: ames!! (Carl S. Gutekunst)
>Romain pointed out that rmail's use of popen was highly questionable; we took
>care of that, too, although we couldn't come up with a way to propogate the
>worm by that means. (Uux eats all the characters that make popen() dangerous.)

The way you get rmail to exploit the popen call is by setting up
the appropriate uucp "From " line. The second word of the line
is passed as the "-fsender" argument to sendmail through the popen
call. Uux doesn't process the text of a message, so you can pass along
whatever shell metacharacters you wish to play games with. This hole
is indepenent of sendmail debug mode, so the popen really does need to go.

	Tim Seaver
	Systems Programmer
	Microelectronics Center of North Carolina