procmail
[Top] [All Lists]

Re: MIME bugs

1998-08-11 17:18:59
On Tue, 11 Aug 1998, D.A. Harris wrote:

: There's been some suggestion on the BUGTRAQ mailing list that procmail 
: could be vulnerable to the MIME related buffer overflows.  Check CERT 
Advisory 
: CA-98.10.  

The CERT advisory (avail. at:
http://www.cert.org/advisories/CA-98.10.mime_buffer_overflows.html
says that only MIME aware mail clients are affected by this bug. Procmail
is not MIME aware (in some cases, it would be nice if it was), so I assume
that it is not affected. Am I missing something? 

Regards,

Andrew

P.S. I think I am not missing something, since the CERT advisory suggests
using John Hardin's filters to *avoid* the problem.