Insecure dependency in open while running with -T switch at /usr/lib/perl/5.10/IO/ and headerless quarantineing

Gabor FUNK FUNK.Gabor at
Sun Nov 22 12:11:27 GMT 2009


>> 1) previously [v4.68.8-1] the
>>   Quarantine Whole Messages As Queue Files = no
>>   worked as intended, but now with 4.78.17-1 it saves
>>   the body ONLY, without the headers.
> What MTA are you using? What are your "Run As User" and "Run As Group" 
> settings? I can't reproduce this. With MTA=sendmail it works fine for me. 
> I get a file for each attachment, and 1 file called "message" which 
> contains the entire message, both headers and body.
> Worked fine with MTA=postfix as well.

I use debian, exim4, run as user/group are Debian-exim.
Was working well before an upgrade, which involved perl library
upgrades. Since problem 2 was the first priority, I didn't do debug
with this, but now I can imagine that this is also caused by some
underlying perl library incompatibility or alike.
If issue 2 is fixed, I will try to play around with this some more and let 
you know.


More information about the MailScanner mailing list