The procmail sanitizer has been updated. The current version is 1.130
It is available via:

US:  http://www.impsec.org/email-tools/procmail-security.html
NO:  http://jhardin.oftedal.no/email-tools/procmail-security.html
AU:  http://grebopple.accessunited.com.au/email-tools/procmail-security.html
AU:  http://impsec.fuzzitech.net/~jhardin/email-tools/procmail-security.html

- From the changelog:

09/08/2001 (1.130)
Moved the embedded "attachment mangled" and "TNEF stripped" texts to
environment variables to improve customizability and reduce the size of the
Sanitizer perl script; see $POISONED_WARNING and $TNEF_WARNING.
Added $SECURITY_DEFANG_SIGNED to allow defanging of signed messages if
you're willing to accept that they will fail the signature check.
Added $SECURITY_TRUST_HTML to disable HTML defanging.
Moved encoded-character decoding to earlier in the HTML defanging process,
so that an obscured tag like "<SCR&amp;#73;PT>" will be properly defanged.
Added defanging of the <LINK> tag.
Added support for mangling and poisoning files with Microsoft Class-ID
Added a check for "already quarantined", so that if your local-rules
script has marked a message to be quarantined the main sanitizer perl
script will be skipped - this saves time processing the message.
Various changes in coding to reduce the size of the sanitizer Perl script -
it should now work successfully on AIX and other OSes with relatively small
command-line size limits. ("Relatively small" he says... :)
Added attempt to defang background images in case they are used as webbugs.
Added a version with the macro scanning code removed to save space and
time if it's not being used.

IMPORTANT NOTE: If you want to mangle CLSID filenames (a good idea) you
MUST update to 1.130 - putting the CLSID regexp into $MANGLE_EXTENSIONS
will wedge a pre-1.130 sanitizer.

The opt-out processor is still cooking. I just realized that the suggested
code clears defaults. Otherwise it would have been included in this

The sanitizer home page is at

