| Newsgroups |
gmane.mail.exmh.devel |
| Message-ID |
<[email protected]> |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
My Sedit users have lately struck a problem with 2.7.0. We decided recently
to disable metamail on our system due to the security vulnerability of
February:
http://www.securiteam.com/unixfocus/5UP0C2KC0W.html
We don't use metamail for message handling, so all was well until upgrading
to 2.7. However, now it appears that metamail is being used (for the first
time?) for Sedit "fixup encoding". Although I could turn this type of
function off completely, it probably means that hard returns will need to
be inserted by the user during edit (and, ugh, reformatting). I've also
tried to convert the unenlightened to vi/fmt but I'm sure you'll understand
the reaction to that!
Considering the response by Debian (Debian Security Advisory DSA 449-1)
to metamail was this:
"We have been devoting some effort to trying to avoid shipping
metamail in the future. It became unmaintainable and these are
probably not the last of the vulnerabilities."
what prompted its integration into a fundamental part of message
composition - and can we back it out again? I'm not worried so much about
being exploited during message editing, but reenabling metamail means
trusting everyone to never, accidentally or otherwise, using the metamail
menu items within incoming messages. I'm extremely loath to treat the
reenabling of metamail as anything more than a stop-gap measure and am
thinking about how I can remove the right-click items if there is no other
solution.
cheers all,
- -- Joel Hatton --
Security Analyst | Hotline: +61 7 3365 4417
AusCERT - Australia's national CERT | Fax: +61 7 3365 7031
The University of Queensland | WWW: www.auscert.org.au
Qld 4072 Australia | Email: [email protected]
-----BEGIN PGP SIGNATURE-----
Comment: Exmh version 2.6.3 04/04/2003
iEYEARECAAYFAkEEVWoACgkQzecFBzFsCPZ93wCglid0f84Wow8vtp0yQoZmIDhs
PIIAoI8Vntu2rc2DH1XRq8bRbenTsxWE
=/Qpe
-----END PGP SIGNATURE-----