Gnus development mailing list
 help / color / mirror / Atom feed
From: Reiner Steib <reinersteib+gmane@imap.cc>
Subject: Re: Gnus vulnerable to virus?
Date: Mon, 12 Dec 2005 19:32:10 +0100	[thread overview]
Message-ID: <v9ek4i415h.fsf@marauder.physik.uni-ulm.de> (raw)
In-Reply-To: <upso2i5g3.fsf@boost-consulting.com>

On Mon, Dec 12 2005, David Abrahams wrote:

> I have always thought, smugly, that by using Gnus I was insulating
> myself from viruses.  However, when I looked at the enclosed email
> under NTEmacs, I got a dialog box saying that no known program could
> open mm.304-VK (actually, the characters after "mm." vary each time I
> look at the email).

Your "possible-virus" has the following MIME structure:

  <* alternative> Re: tangle chairmanship
  <1.* alternative>
  <1.1 text>
  <1.2 html>
  <2 gif>

In the default config, Gnus will automatically display the GIF image.
See the recent thread on "spam mails using image/gif in
multipart/alternative":
<news:v94q5j5m1q.fsf@marauder.physik.uni-ulm.de>
http://thread.gmane.org/v94q5j5m1q.fsf%40marauder.physik.uni-ulm.de

> This seems like it's a few bytes away from being able to run
> arbitrary programs.

Only if you have stupidly configured Gnus to pass MIME types to the
default windows application, e.g. by opening MIME a type with "open".

Bye, Reiner.
-- 
       ,,,
      (o o)
---ooO-(_)-Ooo---  |  PGP key available  |  http://rsteib.home.pages.de/




      reply	other threads:[~2005-12-12 18:32 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-12-12 17:35 David Abrahams
2005-12-12 18:32 ` Reiner Steib [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=v9ek4i415h.fsf@marauder.physik.uni-ulm.de \
    --to=reinersteib+gmane@imap.cc \
    --cc=Reiner.Steib@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).