Re: MIME::Tools Perl module and virus scanners

From: Bennett Todd (betat_private)
Date: Tue Jun 04 2002 - 06:32:06 PDT

  • Next message: zillion: "SRT Security Advisory (SRT2002-06-04-1011): slurp"

    That's good research, and good work.
    
    And I agree with the conclusion you implied:
    
    > If you use MIMEDefang (which uses MIME::Tools), you may want to
    > unconditionally call action_rebuild in filter_begin().  This
    > forces the MIME message to be rebuilt by MIME::Tools, resulting in
    > a valid MIME message.
    
    That's the only approach that offers promise of settling this class
    of problems.
    
    Do MIME::Tools and/or MIMEDefang know about the punctuation marks
    that some Windows MUAs silently ignore in filename extensions? How
    about charset canonicalization, non-default (incorrect but commonly
    accepted) UTF-8 encodings?
    
    -Bennett
    
    
    



    This archive was generated by hypermail 2b30 : Tue Jun 04 2002 - 12:48:38 PDT