Roaring Penguin fixes for "Bypassing SMTP Content Protection with a Flick of a Button"

From: David F. Skoll (dfsat_private)
Date: Thu Sep 12 2002 - 10:06:06 PDT

  • Next message: Jeremy C. Reed: "Re: xbreaky symlink vulnerability"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    Hello,
    
    We at Roaring Penguin Software Inc. have updated our products to deal
    with the vulnerability at http://online.securityfocus.com/archive/1/291514
    
    MIMEDefang:  We have released version 2.21 of MIMEDefang at
    http://www.roaringpenguin.com/mimedefang/  The default filter
    blocks message/partial types.
    
    CanIt:  We have released version 1.2-F17 of our commercial CanIt
    anti-spam solution.  This release is based on MIMEDefang 2.21.
    
    MIME-Tools:  We have updated our patched version of MIME-Tools at
    http://www.roaringpenguin.com/mimedefang/MIME-tools-5.411a-RP-Patched.tar.gz
    MIME-Tools is a Perl module for parsing MIME messages.  The patched
    version now can descend into message/partial as well as message/rfc822
    attachments.  Our patched version also fixes various other vulnerabilities
    in the official package (see http://online.securityfocus.com/archive/1/275282)
    
    Regards,
    
    David.
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://quantumlab.net/pine_privacy_guard/
    
    iD8DBQE9gMmHxu9pkTSrlboRAry3AJ4jE+4XurEOIqPtFt8nxRP6/xE2lQCfdAOw
    QZHmeIlayd8mkMeKTpE0tDU=
    =M+gb
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Thu Sep 12 2002 - 10:29:33 PDT