US-CERT
Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information
 

 View Notes By
Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric

 Other Documents
Technical Alerts

Technical Bulletins

Alerts

Security Tips

Roaring Penguin Software Information for VU#836088

Date Notified:
Date Updated:
Statement Date:
Status Summary:Vulnerable

Vendor Statement

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

We at Roaring Penguin Software Inc. have updated our products to deal
with the vulnerability at
http://online.securityfocus.com/archive/1/291514

MIMEDefang:  We have released version 2.21 of MIMEDefang at
http://www.roaringpenguin.com/mimedefang/  The default filter
blocks message/partial types.

CanIt:  We have released version 1.2-F17 of our commercial CanIt
anti-spam solution.  This release is based on MIMEDefang 2.21.

MIME-Tools:  We have updated our patched version of MIME-Tools at
http://www.roaringpenguin.com/mimedefang/MIME-tools-5.411a-RP-Patched.tar.gz
MIME-Tools is a Perl module for parsing MIME messages.  The patched
version now can descend into message/partial as well as message/rfc822
attachments.  Our patched version also fixes various other vulnerabilities
in the official package (see
http://online.securityfocus.com/archive/1/275282)

Regards,

David.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see
http://quantumlab.net/pine_privacy_guard/

iD8DBQE9gMmHxu9pkTSrlboRAry3AJ4jE+4XurEOIqPtFt8nxRP6/xE2lQCfdAOw
QZHmeIlayd8mkMeKTpE0tDU=
=M+gb
-----END PGP SIGNATURE-----

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

Produced 2009 by US-CERT, a government organization
Disclaimers and copyright information