[Bug 8407] New: URI_DOTCN_SPOOF regex broken - penalizes all CN links

[email protected]
Newsgroups gmane.mail.spam.spamassassin.devel
Message-ID <[email protected]/SpamAssassin/>
https://bz.apache.org/SpamAssassin/show_bug.cgi?id=8407

            Bug ID: 8407
           Summary: URI_DOTCN_SPOOF regex broken - penalizes all CN links
           Product: Spamassassin
           Version: 4.0.2
          Hardware: PC
                OS: Linux
            Status: NEW
          Severity: major
          Priority: P2
         Component: Plugins
          Assignee: [email protected]
          Reporter: [email protected]
  Target Milestone: Undefined

The regex in this penalty is broken:

ifplugin Mail::SpamAssassin::Plugin::URIDetail
  uri_detail   __URI_DOTCN_SPOOF       text =~
m;^https?://(?:[^./]+\.)+(?!cn/)[^/]+/;i domain =~ /\.cn$/i
  meta         URI_DOTCN_SPOOF         __URI_DOTCN_SPOOF
  score        URI_DOTCN_SPOOF         3.000    # limit
  describe     URI_DOTCN_SPOOF         .CN TLD for non-.CN visible URL - likely
Chinese phishing
  tflags       URI_DOTCN_SPOOF         publish
endif  

The regex `^https?://(?:[^./]+\.)+(?!cn/)[^/]+/` is supposed to only match
non-CN domains, but it actually matches all .cn domains as well due to a bug in
how the negative lookahead is specified. The correct regex should be
`^https?://(?:[^./]+\.)+(?!cn/)[^./]+/`.

The result of this bug is that this rule penalizes all emails that contain any
link to a .cn domain, not just .cn links that spoof a non-CN domain.

The severity of this bug is fairly high, because when this rule is turned on,
it causes essentially any email that contains a valid .cn link to be rejected.

-- 
You are receiving this mail because:
You are the assignee for the bug.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.