State of procmail [was Re: Is this the official procmail list?]
Erich Veyhl <[email protected]> Sun, 07 Aug 2016 10:59:04 -0400
| Newsgroups | gmane.mail.procmail |
|---|---|
| Message-ID | <[email protected]> |
--===============0561904295== Content-Type: text/html; charset="us-ascii" <html> <body> An interesting article from 2010 on the state of procmail, the question of the meaning of "dead" open source software, and security:<br><br> <a href="https://lwn.net/Articles/416901/" eudora="autourl"> https://lwn.net/Articles/416901/</a><br><br> "The mail delivery agent (MDA) <a href="http://www.procmail.org/">procmail</a> is a Linux and Unix mainstay; for years it has been the recommended solution for sorting large volume email and filtering out spam. The trouble is that it is dead, and it has been for close to a decade. Or at least that <i>may</i> be the problem, depending on how you look at it. The question of when (or <i>if</i>) to declare an open source project dead does not have a clear answer, and many people still use procmail to process email on high-capacity systems..."<br><br> "...But there are risks inherent in running abandonware, even if it was of stellar quality at the last major release. First and foremost are unfixed security flaws. Mitre.org lists two vulnerabilities affecting procmail since 2001: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2034"> CVE-2002-2034</a>, which allows remote attackers to bypass the filter and execute arbitrary code by way of specially-crafted MIME attachments, and <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5449"> CVE-2006-5449</a>, which uses a procmail exploit to gain access to the Horde application framework. In addition, of course, there are other bugs that remain unfixed. Matthew G. Saroff pointed out one <a href="http://article.gmane.org/gmane.mail.procmail/47672"> long-standing bug</a>, and the procmail site itself <a href="http://www.procmail.org/todo.html">lists</a> a dozen or so known bugs as of 2001.<br><br> "Just as importantly, the email landscape and the system administration marketplace have not stood still since 2001, either. Ed Blackman <a href="http://article.gmane.org/gmane.mail.procmail/47673">noted</a> that procmail cannot correctly handle MIME headers adhering to <a href="http://www.ietf.org/rfc/rfc2047.txt">RFC 2047</a> (which include non-ASCII text), despite the fact that RFC 2047 dates back to 1996. RFC 2047-formatted headers are far from mandatory, but they do continue to rise in frequency."<br><br> <br><br> </body> </html> --===============0561904295== Content-Type: text/plain; charset="iso-8859-1" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline ____________________________________________________________ procmail mailing list Procmail homepage: http://www.procmail.org/ [email protected] http://mailman.rwth-aachen.de/mailman/listinfo/procmail --===============0561904295==--