Bonum Certa Men Certa

Edward Brocklesby: hacker received advance notice of zero-day vulnerabilities in MH and NMH email software

posted by Roy Schestowitz on Jun 15, 2024

Reprinted with permission from Daniel Pocock.

The web page for nmh, a UNIX mail client, tells us that versions prior to 1.0.3 had a back door:

All versions of nmh prior to 1.0.3 (as well as MH) contained a vulnerability where incoming mail messages with carefully designed MIME headers could cause the mhshow command to execute arbitrary shell code.

Brocklesby was maintainer of the MH package and therefore he received advance warning of the security vulnerability in both MH and NMH software. The warning was circulated in the debian-private cubby house approximately four days before a public bug report appeared. He may have received other personal emails or IRC chat messages about the issue before anybody else had time to protect their systems.

Subject: FWD: MH also vulnerable to remote attack (was Re: nmh security update)
Date: Fri, 3 Mar 2000 19:10:19 -0800
From: Joey Hess <joeyh@debian.org>
To: Edward Brocklesby <ejb@debian.org>
CC: security@bugs.debian.org

We've patched nmh, but it looks like mh may be vunerable to the same hole.
----- Forwarded message from Dan Harkless <dan-bugtraq@DILVISH.SPEED.NET> -----
Date: Thu, 2 Mar 2000 16:37:37 -0800 From: Dan Harkless <dan-bugtraq@DILVISH.SPEED.NET> Subject: MH also vulnerable to remote attack (was Re: nmh security update) To: BUGTRAQ@SECURITYFOCUS.COM
Ruud de Rooij <ruud@RUUD.ORG> writes: > Versions prior to 1.0.3 of the nmh package contained a vulnerability > where incoming mail messages with carefully designed MIME headers could > cause nmh's mhshow command to execute arbitrary shell code. > > This bug has been fixed in nmh 1.0.3 and we encourage you to upgrade > immediately. The fixed package is available at > > ftp://ftp.mhost.com/pub/nmh/nmh-1.0.3.tar.gz > > The MD5sum of nmh-1.0.3.tar.gz is 02519bf8f7ff8590ecfbee9f9500ea07.
Please note that the MIME-handling code with the security hole dates back to nmh's ancestor MH, so MH users (at least those using latter-day versions with MIME capability) are also strongly encouraged to upgrade to nmh 1.0.3.
---------------------------------------------------------------------- Dan Harkless | To prevent SPAM contamination, please dan-bugtraq@dilvish.speed.net | do not mention this private email SpeedGate Communications, Inc. | address in Usenet posts. Thank you.
----- End forwarded message -----
-- see shy jo

The rogue elements of Debian spent over $120,000 to attack my family and I with lawyers after my father died. They made no credible inquiry into the activities of real hackers. They only care about making political attacks on volunteers and our families. Security is above their pay grade.

It is now ten days after my first disclosure about the Edward Brocklesby affair and there is no comment whatsoever from the Debian security team. The only comments they make are to attack my family and I, a reprisal for raising another serious security concern.

Read more articles about the mysterious Edward Brocklesby & Debian affair.

Other Recent Techrights' Posts

The Cyber Show: Remember That Code is Art
The article is very long, very profound, and speaks of "the next installation"
Only Days After Mass Layoffs in Microsoft's Azure There Are Headlines About Much-Expected XBox Layoffs
XBox as a console is basically dead or "fast-dying"
SLAPP Censorship - Part 103 Out of 200: Telling People What They Know and Don't Know About Death Threats They Receive
patronising letters sent on behalf of the Serial Strangler from Microsoft
IBM Genies in the Bottle
for ordinary people working who at at IBM, it's not hard to see that IBM is floundering
 
Links 12/06/2026: "NearlyFreeSpeech" No More, Openwashing by Google (DiffusionGemma)
Links for the day
Today There's a Massive EPO Strike (Like Every Friday), Workers Explain Further Cuts Despite the EPO Making More Income by Granting Illegal Patents (or Invalid Patents Illegally)
"Recent exchange with the Administration on the implications of the SAP on the Education and Childcare Allowance"
Communicating With Freedom - Part IV - Quibble Now in quibble.chat, Open for Contributions Via Codeberg
Today we continue the series about Quibble
European Patent Office (EPO) Series: The Importance of Having "Pals from the Palacete"
for his reappointment bid to succeed, Campinos will need to be able to rely on the support of both the Portuguese Prime Minister, Luís Montenegro, and the President of the European Council, António Costa
Cyber Show on How Updates or Upgrades Break Workflows, Even in Free Software
"We did a big upgrade on the AV production pipeline"
Discussions About IBM Layoffs in June, Including by RTO and PIPs
mass layoffs are becoming increasingly difficult to conceal
Gemini Links 12/06/2026: Decks and Work Essay
Links for the day
"Rolling Strikes" Continue at the European Patent Office, the Administrative Council Needs to Take Action Against Crooked Office Management
This coming weekend we'll talk about some of the other issues and concerns expressed by the union
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, June 11, 2026
IRC logs for Thursday, June 11, 2026
Links 11/06/2026: Disputes Over Copyright Infringement, Failure to Meet Climate Goals, "ChatGPT Caught Recommending “Products” That Are Just Scams"
Links for the day
Gemini Links 11/06/2026: Programmable Systems and Slop "is Coming for Your Serifs"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, June 10, 2026
IRC logs for Wednesday, June 10, 2026
Links 11/06/2026: LF Openwashing of Slop and "Azerbaijan Bans TikTok and Other Social Media Apps in School"
Links for the day
European Patent Office (EPO) Series: The Centre (in Portugal) Falls Apart…
Luís Montenegro became embroiled in a conflict-of-interest controversy
IBM Lost About 18% of Its "Market Value" This Month
In IBM's case, a lot of the latest "pump" was Arvind's "quantum" hype/fantasy
Gemini Links 10/06/2026: Signal to Noise, Cancer, and Permacomputing
Links for the day
Links 10/06/2026: More Microsoft Layoffs, Sweden to "Ban Mobile Phones in Schools"
Links for the day
Communities and "Prosumers."
today's meetup will be about community
Gemini and Gopher Links 10/06/2026: Roasting, Changes, and Harms of Slop
Links for the day
Microsoft Azure Shrinking With More Mass Layoffs
"Reports suggest the layoffs will impact close to 200 out of 400 workers, who are set to cease employment at Azure on July 6"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, June 09, 2026
IRC logs for Tuesday, June 09, 2026