Hi,
I have qmail-scanner 1.24 with clamd installed.
I don't know if i'm right but maybe you forgot to update some
email_sender subroutine checks when you added the 'psender' option
for notification. When $NOTIFY_ADDRS includes 'psender', during
policy quarantine notification the email delivered to psender can
leak information about the path and the name of the file in the
quarantine directory.
I resolved this changing from
 
if ($addr_type ne "sender")
 
 to
 
 if ($addr_type !~ /sender/)
 
 Please let me now if i'm right
 
 Thanks
Francesco


-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now. 
http://productguide.itmanagersjournal.com/
_______________________________________________
Qmail-scanner-general mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general

Reply via email to