Patch for new virus - Mabuto.B or Mabutu-A

Julian Field mailscanner at ecs.soton.ac.uk
Wed Oct 27 13:44:51 IST 2004


If it works for you without the patch, then carry on as you are. A
properly-fixed version of MIME-tools will be released at some point later
today (though I don't know the timezone of that statement), at which point
I'll do another beta release.

Hopefully that will be the last update before the next stable release.


On 27/10/04 1:28 pm, "Ryan Pitt" <ryan at MARINOCRANE.COM> wrote:

> At the risk of being redundant...
> Here too, without the patch...
> Does this mean that it is not necessary to patch right away?
> Can we wait until the next stable release which should include the patch?
>
> ***This output from MailWatch***
> Sophos: >>> Virus 'W32/Mabutu-A' found in file
> ./i9P19KD1011381/britney.zip/britney.jpg .scr ClamAV: britney.zip
> contains Worm.Mabutu.A-unp
> Bitdefender: Found virus Win32.Mabutu.A at mm in file britney.zip
> Sophos: >>> Virus 'W32/Mabutu-A' found in file
> ./i9P19KD1011381/britney.jpg .scr
> ClamAV: britney.jpg .scr contains Worm.Mabutu.A-unp
> Bitdefender: Found virus Win32.Mabutu.A at mm in file britney.jpg .scr
> MailScanner: Very long filenames are good signs of attacks against
> Microsoft e-mail packages (britney.jpg .scr)
>
> Sophos: >>> Virus 'W32/Mabutu-A' found in file
> ./i9P19KD1011381/britney.jpg .scr ClamAV: britney.jpg .scr contains
> Worm.Mabutu.A-unp
> Bitdefender: Found virus Win32.Mabutu.A at mm in file britney.jpg .scr
> MailScanner: Very long filenames are good signs of attacks against
> Microsoft e-mail packages (britney.jpg .scr)
>
> Thanks and Regards
> Ryan
>
> Felipe Tonioli wrote:
>
>> Catch here too without the patch...
>>
>> Worm.Mabutu.A-unp ClamAV 29/09/04 02:16:53 2
>> Win32.Mabutu.A at mm BitDefender 29/09/04 02:16:53 2
>>
>>
>>
>> On Wed, 27 Oct 2004 09:40:21 +0100, Martin Hepworth
>> <martinh at solid-state-logic.com> wrote:
>>
>>
>>> Julian
>>>
>>> FYI i patched my 4.32.5 on FreeBSD with no issues.
>>>
>>> However I did catch a Mabutu-A last night without the patch, both
>>> SophosSAVI and CLAMAV (command line, not module) caught it.
>>>
>>> my MIME:: modules are the following versions (prob from about a year ago
>>> when I first installed MS)
>>>
>>> 5.403   MIME::Decoder
>>> 5.403   MIME::Decoder::UU
>>> 5.403   MIME::Head
>>> 5.406   MIME::Parser
>>> 5.411   MIME::Tools
>>>
>>> --
>>> Martin Hepworth
>>> Snr Systems Administrator
>>> Solid State Logic
>>> Tel: +44 (0)1865 842300
>>>
>>>
>>>
>>
>>
>>
>
> ------------------------ MailScanner list ------------------------
> To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
> 'leave mailscanner' in the body of the email.
> Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and
> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).
>

--
Julian Field
www.MailScanner.info
Buy the MailScanner book at www.MailScanner.info/store

PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654

------------------------ MailScanner list ------------------------
To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and
the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).




More information about the MailScanner mailing list