[Mimedefang] Email injection and the android 'email' app

David F. Skoll dfs at roaringpenguin.com
Tue Mar 5 17:59:02 EST 2013

On Tue, 5 Mar 2013 17:45:01 -0500
"Dale Moore" <Dale.Moore at cs.cmu.edu> wrote:

> From the users perspective our system lost their email.... again.
> This application works for hundreds or thousands of other sites and
> it doesn't work for our system.  From their perspective, our setup
> is just plain broken.

I would file a bug with the authors of the application in question, and
I'd notify all your users of the bug and advise them to switch to
a different email application if they send mail via your servers.

There's no way you should break your setup to comply with a brain-dead
Android app.



