Gnus development mailing list
 help / color / mirror / Atom feed
From: Eze Ogwuma <typhoon@dircon.co.uk>
Subject: [Brent Welch <welch@scriptics.com>] MIME attack on Microsoft and Netscape mail readers
Date: 29 Jul 1998 23:57:49 +0100	[thread overview]
Message-ID: <m3lnpcp8nm.fsf@localhost.localdomain> (raw)

Hi,

Does anyone have any thoughts on this and its possible interaction
with Gnus and TM?
-- 
Eze Ogwuma
------- Start of forwarded message -------
Resent-Date: 29 Jul 1998 19:02:46 -0000
Resent-Cc: recipient list not shown:;
Message-Id: <199807291901.MAA20280@pop.scriptics.com>
To: exmh-users@redhat.com
Subject: MIME attack on Microsoft and Netscape mail readers
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Date: Wed, 29 Jul 1998 12:01:46 -0700
From: Brent Welch <welch@scriptics.com>
Resent-Message-ID: <"4eCFO.0.5K6.K7tlr"@mail2.redhat.com>
Resent-From: exmh-users@redhat.com
Resent-Reply-To: exmh-users@redhat.com
Resent-Sender: exmh-users-request@redhat.com

I've put the following notice on http://www.beedub.com/exmh/

"Recent news articles about security flaws in Microsoft and Netscape mail
readers concern an attack on MIME handling.
Exmh implements MIME handling in Tcl code that is unaffected by
buffer overflow type attacks.  There are no fixed sized buffers
in the implementation of Tcl itself, so it is not possible to
trick Exmh into executing arbitrary code by sending it
MIME attachments with extremely long file names."

--	Brent Welch	<welch@scriptics.com>
	http://www.scriptics.com
	Scriptics: The Tcl Platform Company



-- 
         To unsubscribe: mail exmh-users-request@redhat.com with 
                       "unsubscribe" as the Subject.



------- End of forwarded message -------


             reply	other threads:[~1998-07-29 22:57 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
1998-07-29 22:57 Eze Ogwuma [this message]
1998-07-30  0:35 ` SL Baur
1998-07-30  0:43   ` William M. Perry
1998-07-31  6:25     ` SL Baur

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=m3lnpcp8nm.fsf@localhost.localdomain \
    --to=typhoon@dircon.co.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).