Comment 2 for bug 85033

Revision history for this message
Jakob Østergaard (joe-evalesco) wrote :

Thank you for the reply!

I think you misunderstood my intentions. I guess I confused matters by pointing to the broken fix in 1.4. Let's forget everything about 1.4, Edgy and Feisty, and start over :)

This is the problem:
 Version 1.2a currently shipped with Dapper will segfault on bad mime input.

This is the impact:
 Anyone can DoS a mail system running Dapper and Spamprobe by sending bad mime data (the mailer will, in common setups, queue the message that caused the segfault and re-try the delivery to spamprobe for a long long time).

This is the solution:
 I sent a patch which fixes 1.2a.

Can we include that solution (or any other solution) so that 1.2a in Dapper works?