Vulnerability Development mailing list archives

Re: No body emails and Norton antivirus


From: Peter Lem <peter.lem () acml com>
Date: 7 Oct 2004 12:50:24 -0000

In-Reply-To: <20040925222930.GA2041 () commedia it>

Version of Norton Anti-Virus?  patched?
Version of Outlook? patched?

Thank You.

Received: (qmail 13508 invoked from network); 27 Sep 2004 16:45:53 -0000
Received: from mail2.securityfocus.com (205.206.231.1)
 by mail.securityfocus.com with SMTP; 27 Sep 2004 16:45:53 -0000
Received: (qmail 2666 invoked by alias); 27 Sep 2004 16:48:34 -0000
Delivered-To: archive-vuln-dev () securityfocus com
Received: (qmail 2660 invoked from network); 27 Sep 2004 16:48:34 -0000
Received: from outgoing.securityfocus.com (HELO outgoing3.securityfocus.com) (205.206.231.27)
 by mail2.securityfocus.com with SMTP; 27 Sep 2004 16:48:34 -0000
Received: from lists.securityfocus.com (lists.securityfocus.com [205.206.231.19])
      by outgoing3.securityfocus.com (Postfix) with QMQP
      id 451F3236F9F; Mon, 27 Sep 2004 10:32:56 -0600 (MDT)
Mailing-List: contact vuln-dev-help () securityfocus com; run by ezmlm
Precedence: bulk
List-Id: <vuln-dev.list-id.securityfocus.com>
List-Post: <mailto:vuln-dev () securityfocus com>
List-Help: <mailto:vuln-dev-help () securityfocus com>
List-Unsubscribe: <mailto:vuln-dev-unsubscribe () securityfocus com>
List-Subscribe: <mailto:vuln-dev-subscribe () securityfocus com>
Delivered-To: mailing list vuln-dev () securityfocus com
Delivered-To: moderator for vuln-dev () securityfocus com
Received: (qmail 28340 invoked from network); 25 Sep 2004 16:41:35 -0000
Date: Sun, 26 Sep 2004 00:29:30 +0200
From: zerozero () controcultura net
To: vuln-dev () securityfocus com
Subject: No body emails and Norton antivirus
Message-ID: <20040925222930.GA2041 () commedia it>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
X-Spam-Checker-Version: SpamAssassin 2.64 (2004-01-11) on mail.commedia.it
X-Spam-Level: 
X-Spam-Status: No, hits=-4.7 required=5.0 tests=BAYES_00,NO_REAL_NAME autolearn=no version=2.64

Hello,
 we're getting reports from our customers about 
Outlook + Norton Antivirus crashing on certain messages. 
We tryed to track the problem down, and it seems like that
emails without body and without the \n separating the body
from the headers crashes them. We had not the time to track
the problem down any further, but can anybody confirm this?
Many mail servers accept mails ``without body''.
 We couldn't reproduce it on _all_ platforms, but we
experienced the problem on many installations.

 You can generate a simple test case by sending a 
message to your account using something like:

telnet mail 25
...
rcpt to: ...
data
From: foo () bar org
To: myaccount () test com
Subject: test email
.
quit

 Please make sure the MDA on your server does not
automatically insert a \n after the headers (Subject
should be on the last line -- I think spamassassin, 
procmail and many others do this...).

Thanks for any replay,
Cheers,
zero



Current thread: