[Mimedefang] REPOST: SECURITY: MIME-tools patch

David F. Skoll dfs at roaringpenguin.com
Wed Oct 27 07:33:55 EDT 2004


On Tue, 26 Oct 2004, Kevin A. McGrail wrote:

> What is your opinion of the severity of the bug?  Does it crash MD?  Will an
> A/V scan still detect the issue?

- It will not crash MD.
- Clam will probably still detect the virus if you use the
  md_copy_orig_msg_to_work_dir_as_mbox_file() call in your filter.  But I have
  not tested this.

Nevertheless, it's best to fix the bug because it could allow attackers to
sneak unapproved parts through MIMEDefang.

Regards,

David.



More information about the MIMEDefang mailing list