[Esd-l] WARN: malformed MIME can bypass sanitizer

John D. Hardin jhardin at impsec.org
Mon Sep 22 08:10:11 PDT 2003


A worm showed up unsanitized in my mailbox this morning. Investication
showed that one of the MIME boundary strings was malformed: it did not
begin with "--" as per RFC2046 (it began with "A--"). The sanitizer
didn't parse it properly, but the mailer (evolution) did.

I will modify the sanitizer to fix MIME boundary headers malformed in
this manner, but I won't be able to release it right away, so this is
a heads-up.

