1. 07 Jan, 2013 1 commit
  2. 03 Jan, 2012 1 commit
  3. 16 Nov, 2011 1 commit
    • Thomas Sibley's avatar
      Iterate attachments as the creator of the current transaction when sending mail · c29107c6
      Thomas Sibley authored
      Check CurrentUserCanSee before trying to add an attachment since it
      could otherwise end up empty now that we have the correct current user.
      
      Additionally, simply check RT::Transaction's CurrentUserCanSee when
      iterating inside an RT::Attachments object rather than maintaining a
      different but similar conditional tree.  CurrentUserCanSee correctly
      access checks transaction types like EmailRecord, for example.
      
      This resolves part of CVE-2011-2084.
      c29107c6
  4. 03 Mar, 2011 1 commit
  5. 15 Feb, 2011 3 commits
  6. 28 Dec, 2010 5 commits
  7. 19 Sep, 2010 2 commits
  8. 29 Jul, 2010 2 commits
  9. 06 Jan, 2009 2 commits
  10. 04 Dec, 2008 1 commit
  11. 11 Jul, 2008 1 commit
  12. 09 Jun, 2008 1 commit
  13. 24 Apr, 2008 1 commit
  14. 11 Apr, 2008 2 commits
  15. 28 Feb, 2008 1 commit
  16. 07 Aug, 2007 1 commit
  17. 26 May, 2007 3 commits
  18. 22 May, 2007 1 commit
  19. 01 May, 2007 1 commit
  20. 24 Apr, 2007 2 commits
  21. 22 Mar, 2007 4 commits
  22. 05 Mar, 2007 1 commit
  23. 27 Oct, 2006 2 commits