The procmail sanitizer has been updated. The current version is 1.131
It is available via:

US:  http://www.impsec.org/email-tools/procmail-security.html
NO:  http://jhardin.oftedal.no/email-tools/procmail-security.html
AU:  http://grebopple.accessunited.com.au/email-tools/procmail-security.html
AU:  http://impsec.fuzzitech.net/~jhardin/email-tools/procmail-security.html

- From the changelog:

11/22/2001 (1.131)
Fixed the script so that it now actually respects the setting of
Added support for the Perl regular expression (?...) construct in the poisoned
files list, so that more flexible poisoning lists may be constructed - see man
perlex for details. See the recommended poison list for examples.
Fixed a bug that caused the sanitizer to misinterpret multi-line RFC822
Content-Type headers, leading to attachments not being sanitized.
Added a hack to recognize filenames in Content-Description comment headers,
where MS Outlook helpfully looks for a filename if one isn't specified in
the Content-Type or Content-Disposition headers; if you don't want
Content-Description to be modified, define $SECURITY_DISABLE_OUTLOOK_HACKS to
be any value.
Recognize multipart attachment specification where the MIME boundary string is
not in quotes.
Added $SECURITY_NONOTIFY_LONGSUBJECT to suppress long-subject-header
Remove trailing spaces from attachment filenames.
Remove trailing spaces if truncating long attachment filename with embedded
Defer echo of Content-Type and Content-Transfer-Encoding headers to remove
the need for default filename generation and to make inserted warnings
display properly.
Fix misparsing of the attachment following an empty attachment.
Cosmetic fix in one warning message.
Added $STRIPPED_EXECUTABLES to strip attachments by name in a manner similar to
$POISONED_EXECUTABLES - stripping an attachment does not poison the entire

All of these new things may once again make the script too big for AIX...
If so, try the no-macro-scan version.

The opt-out processor appears stable. ISP's really should take a look at it.

The sanitizer home page is at

