[Mimedefang] [OT] FYI: Clam AntiVirus UUencoded Message Denial of Service Vulnerability

David F. Skoll dfs at roaringpenguin.com
Tue Feb 10 12:10:40 EST 2004


On Tue, 10 Feb 2004, Chris Myers wrote:

> For those of us using Clamd 0.65, fyi.

The normal way of using Clam with MIMEDefang will not trigger this bug,
because we don't invoke clam with the --mbox option.  That means it won't
try to unpack MIME or uuencoded messages.

However, if you've modified the clam configuration file to include this
option, then you may be vulnerable.

Regards,

David.



More information about the MIMEDefang mailing list