LWN.net Logo

MIMEDefang version 2.21 scans fragmented mail messages

From:  "David F. Skoll" <dfs@roaringpenguin.com>
To:  bugtraq@securityfocus.com
Subject:  Roaring Penguin fixes for "Bypassing SMTP Content Protection with a Flick of a Button"
Date:  Thu, 12 Sep 2002 13:06:06 -0400 (EDT)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

We at Roaring Penguin Software Inc. have updated our products to deal
with the vulnerability at http://online.securityfocus.com/archive/1/291514

MIMEDefang:  We have released version 2.21 of MIMEDefang at
http://www.roaringpenguin.com/mimedefang/  The default filter
blocks message/partial types.

CanIt:  We have released version 1.2-F17 of our commercial CanIt
anti-spam solution.  This release is based on MIMEDefang 2.21.

MIME-Tools:  We have updated our patched version of MIME-Tools at
http://www.roaringpenguin.com/mimedefang/MIME-tools-5.411a-RP-Patched.tar.gz
MIME-Tools is a Perl module for parsing MIME messages.  The patched
version now can descend into message/partial as well as message/rfc822
attachments.  Our patched version also fixes various other vulnerabilities
in the official package (see http://online.securityfocus.com/archive/1/275282)

Regards,

David.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://quantumlab.net/pine_privacy_guard/

iD8DBQE9gMmHxu9pkTSrlboRAry3AJ4jE+4XurEOIqPtFt8nxRP6/xE2lQCfdAOw
QZHmeIlayd8mkMeKTpE0tDU=
=M+gb
-----END PGP SIGNATURE-----



(Log in to post comments)

Copyright © 2002, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds