Home page logo

bugtraq logo Bugtraq mailing list archives

Outlook \r expliots - ripMIME fix.
From: Paul L Daniels <pldaniels () pldaniels com>
Date: Mon, 18 Feb 2002 15:43:53 +1000

A recent announcement of ripMIME 1.2.12 has been superceded with a new release which covers several issues as mentioned 
in 3APA3A () SECURITY NNOV RU's content-exploits analysis post.


        "\0 data poisoning" and "fake-end-of-line termination" (due to fgets()) have been immediately covered.

Issues with UTF formatting is still present (although detection of the data content is not affected, as 
content-scanners should not use the file name as anything more than a subtle-guide).

        ripMIME is available at http://pldaniels.org/ripmime


Paul L Daniels    http://www.pldaniels.com
Linux/Unix systems    Internet Development
A.B.N. 19 500 721 806

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]