State of procmail [was Re: Is this the official procmail list?]

Erich Veyhl <[email protected]> Sun, 07 Aug 2016 10:59:04 -0400
Newsgroups gmane.mail.procmail
Message-ID <[email protected]>
--===============0561904295==
Content-Type: text/html; charset="us-ascii"

<html>
<body>
An interesting article from 2010 on the state of procmail, the question
of the meaning of &quot;dead&quot; open source software, and
security:<br><br>
<a href="https://lwn.net/Articles/416901/" eudora="autourl">
https://lwn.net/Articles/416901/</a><br><br>
&quot;The mail delivery agent (MDA)
<a href="http://www.procmail.org/">procmail</a> is a Linux and Unix
mainstay; for years it has been the recommended solution for sorting
large volume email and filtering out spam. The trouble is that it is
dead, and it has been for close to a decade. Or at least that <i>may</i>
be the problem, depending on how you look at it. The question of when (or
<i>if</i>) to declare an open source project dead does not have a clear
answer, and many people still use procmail to process email on
high-capacity systems...&quot;<br><br>
&quot;...But there are risks inherent in running abandonware, even if it
was of stellar quality at the last major release. First and foremost are
unfixed security flaws. Mitre.org lists two vulnerabilities affecting
procmail since 2001:
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2034">
CVE-2002-2034</a>, which allows remote attackers to bypass the filter and
execute arbitrary code by way of specially-crafted MIME attachments, and
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5449">
CVE-2006-5449</a>, which uses a procmail exploit to gain access to the
Horde application framework. In addition, of course, there are other bugs
that remain unfixed. Matthew G. Saroff pointed out one
<a href="http://article.gmane.org/gmane.mail.procmail/47672">
long-standing bug</a>, and the procmail site itself
<a href="http://www.procmail.org/todo.html">lists</a> a dozen or so known
bugs as of 2001.<br><br>
&quot;Just as importantly, the email landscape and the system
administration marketplace have not stood still since 2001, either. Ed
Blackman
<a href="http://article.gmane.org/gmane.mail.procmail/47673">noted</a>
that procmail cannot correctly handle MIME headers adhering to
<a href="http://www.ietf.org/rfc/rfc2047.txt">RFC 2047</a> (which include
non-ASCII text), despite the fact that RFC 2047 dates back to 1996. RFC
2047-formatted headers are far from mandatory, but they do continue to
rise in frequency.&quot;<br><br>
<br><br>
</body>
</html>


--===============0561904295==
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

____________________________________________________________
procmail mailing list   Procmail homepage: http://www.procmail.org/
[email protected]
http://mailman.rwth-aachen.de/mailman/listinfo/procmail
--===============0561904295==--