Debian Bug report logs - #433295
amavisd-new: Banned rule "Windows Class ID ext. - CLSID" side effect

version graph

Package: amavisd-new; Maintainer for amavisd-new is Brian May <[email protected]>; Source for amavisd-new is src:amavisd-new (PTS, buildd, popcon).

Reported by: Polish <[email protected]>

Date: Mon, 16 Jul 2007 07:18:02 UTC

Severity: minor

Found in version amavisd-new/1:2.4.2-6.1

Full log


Message #10 received at [email protected] (full text, mbox, reply):

Received: (at 433295) by bugs.debian.org; 16 Jul 2007 15:13:23 +0000
From [email protected] Mon Jul 16 15:13:23 2007
Return-path: <[email protected]>
Received: from out2.smtp.messagingengine.com ([66.111.4.26])
	by rietz.debian.org with esmtp (Exim 4.50)
	id 1IASGJ-0005Sg-Qb
	for [email protected]; Mon, 16 Jul 2007 15:13:23 +0000
Received: from compute1.internal (compute1.internal [10.202.2.41])
	by out1.messagingengine.com (Postfix) with ESMTP id 09F629C1A;
	Mon, 16 Jul 2007 11:13:23 -0400 (EDT)
Received: from heartbeat1.messagingengine.com ([10.202.2.160])
  by compute1.internal (MEProxy); Mon, 16 Jul 2007 11:13:23 -0400
X-Sasl-enc: LpRQrImCfM5T6xKyyX+f/kUYawn/5IS5/jccadDrZHAC 1184598802
Received: from khazad-dum.debian.net (unknown [201.82.227.152])
	by mail.messagingengine.com (Postfix) with ESMTP id 6D93B636E;
	Mon, 16 Jul 2007 11:13:22 -0400 (EDT)
Received: from localhost (localhost [127.0.0.1])
	by localhost.khazad-dum.debian.net (Postfix) with ESMTP id 8266B28B20;
	Mon, 16 Jul 2007 12:13:20 -0300 (BRT)
X-Virus-Scanned: Debian amavisd-new at khazad-dum.debian.net
Received: from khazad-dum.debian.net ([127.0.0.1])
	by localhost (khazad-dum.debian.net [127.0.0.1]) (amavisd-new, port 10024)
	with LMTP id oDCPcbakYX1v; Mon, 16 Jul 2007 12:13:19 -0300 (BRT)
Received: by khazad-dum.debian.net (Postfix, from userid 1000)
	id 6B7BC28B23; Mon, 16 Jul 2007 12:13:19 -0300 (BRT)
Date: Mon, 16 Jul 2007 12:13:19 -0300
From: Henrique de Moraes Holschuh <[email protected]>
To: Polish <[email protected]>, [email protected]
Subject: Re: Bug#433295: amavisd-new: Banned rule "Windows Class ID ext. -
	CLSID" side effect
Message-ID: <[email protected]>
References: <[email protected]>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <[email protected]>
X-GPG-Fingerprint: 1024D/1CDB0FE3 5422 5C61 F6B7 06FB 7E04  3738 EE25 DE3F
	1CDB 0FE3
User-Agent: Mutt/1.5.16 (2007-06-11)
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
	(1.212-2003-09-23-exp) on rietz.debian.org
X-Spam-Level: 
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,FROMDEVELOPER,
	HAS_BUG_NUMBER,RCVD_IN_SBLXBL,RCVD_IN_SBLXBL_CBL autolearn=no 
	version=2.60-bugs.debian.org_2005_01_02
On Mon, 16 Jul 2007, Polish wrote:
> Package: amavisd-new
> Version: 1:2.4.2-6.1
> Severity: minor
> 
> Banned rule CLSID is enabled by default. Rule matchs mail with spam in
> attachment. Problem is that rule match attachment with name "{Spam?}". 
> 
> User1 mails to user2. Mail system marks valid mail as spam. User2 resent mail
> in attachment to Administrator, but mail system block mail, bacause
> match CLSID rule. 

Would you take just documentation of this issue as a valid fix? I am
severely inclined to prefer blocking a big class of attacks on windows
platforms in amavisd-new over letting email with weird crap as an attachment
name...

I don't know if fixing the regex to require numbers after the '?' would work
well as a fix (we must not make it fail to match any CLSID attacks).  Brian?

-- 
  "One disk to rule them all, One disk to find them. One disk to bring
  them all and in the darkness grind them. In the Land of Redmond
  where the shadows lie." -- The Silicon Valley Tarot
  Henrique Holschuh



Send a report that this bug log contains spam.


Debian bug tracking system administrator <[email protected]>. Last modified: Fri May 16 04:54:06 2025; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU General Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.