Re: [Full-Disclosure] [ GLSA 200501-46 ] ClamAV: Multiple issues

From: exon (exon_at_home.se)
Date: 02/02/05

  • Next message: Viktor E Larionov: "Re[2]: WinAmp POC: How to get 900+ shellcodespace!?"
    Date: Wed, 02 Feb 2005 20:17:46 +0100
    To: bugtraq@securityfocus.com
    
    

    Trog wrote:
    > On Tue, 2005-02-01 at 14:41 -0800, Dack wrote:
    >
    >>>>By sending a base64 encoded image file in a URL an attacker could evade
    >>>>virus scanning.
    >>>
    >>>It's somewhat harsh to single out ClamAV for this issue. AFAICT, the
    >>>only two virus scanners that do currently protect against this are
    >>
    >>What mail clients, if any, would execute a virus encoded in this manner?
    >>Is this a gaping hole in other mail anti-virus systems, or do most
    >>clients just ignore this kind of data?
    >
    >
    > I really haven't tested mail clients, but Thunderbird would be the most
    > likely.
    >

    Nopes. Thunderbird, being a client designed to run under a plethora of
    platforms, doesn't bother with executing code at all unless explicitly
    asked to. In my opinion that's one of its greatest feature.


  • Next message: Viktor E Larionov: "Re[2]: WinAmp POC: How to get 900+ shellcodespace!?"

    Relevant Pages

    • Re: email & creativity
      ... Does not matter in the slightest. ... You will not be able to execute ... javascript in mail clients. ...
      (comp.lang.javascript)
    • Re: Email clients
      ... > mail clients that run on both my FBSD box and to run on my Window box. ... I'd try Mozilla or Thunderbird. ... Mozilla is available for FreeBSD via packages (it's included on the install ...
      (freebsd-questions)
    • Re: [opensuse] off-list replies
      ... hitting reply on my copy of Thunderbird will send directly to the ... original sender not to the list itself. ... (I dunno if this case with other ... mail clients). ...
      (SuSE)
    • Re: Mailing List Replies?
      ... back to the poster and not back to the list? ... Many mail clients have a "Reply to list" function. ... Thunderbird could reply to the newsgroup directly. ... But Gmail seems doesn't have this feature. ...
      (perl.beginners)
    • Re: Email merge from word to apple mail???
      ... Thunderbird and a few other mail clients are working on providing MAPI ... *only* client that can support this action why not allow word to submit all ...
      (microsoft.public.mac.office.word)

  • Quantcast