[Esa-l] ANN: Sanitizer update

John D. Hardin jhardin at wolfenet.com
Tue Sep 19 14:19:30 PDT 2000

Hash: SHA1

The procmail sanitizer has been updated. The current version is 1.118
It is available via:

US: http://www.impsec.org/email-tools/procmail-security.html
US: ftp://ftp.rubyriver.com/pub/jhardin/antispam/procmail-security.html
CAN: ftp://netserv.on.ca/pub/jhardin/antispam/procmail-security.html
EU: ftp://kanon.net/pub/jhardin/antispam/procmail-security.html

- From the News section of the home page:

Added .DLL, .MDA and .MDW to the default mangle list - if you are maintaining
custom mangle lists, you should update them. You probably also want to add
*.DLL to your poisoned-attachments list.
Modified the macro scanner slightly to reduce the chance of false positives on
Excel spreadsheets.
Added From:, Status:, X-Status: and X-Keywords: to the excessively-long headers
check since UW IMAP is vulnerable to overflows in these.
Increased the Excessively Long Header length to 512 characters to further
reduce false positives.

Also, the sanitizer, home page, gateway nano-HOWTO and a list of poisoned
filespecs is now available as a tarball.

The sanitizer home page is moving to

Version: PGP 5.0
Charset: noconv


