Hello,

On Thursday, 7. August 2008 15:48:21 Mark Martinec wrote:
> > > On our amavisd-new box:
> > Jul 30 16:36:42 mail kernel: [608438.105690] lha[700]: segfault at
> > bfcf4d55
> >
> > ...
> >
> Yes.
> Any crash caused by data over which one has no control
> is a potential security risk and a cause for concern.
>
> LHa decoder can be disabled by removing (or commenting-out) its entry
> in the @decoders list, or by just making the lha program unavailable
> (renaming or deinstalling it).

Picking up an old thread here. 

What about using 7zip for lha decompression?
The 7zip code is maintained and looks way more
secure than the old lha code.

Best regards,
Thomas

------------------------------------------------------------------------------
This SF.net email is sponsored by Sprint
What will you do first with EVO, the first 4G phone?
Visit sprint.com/first -- http://p.sf.net/sfu/sprint-com-first
_______________________________________________
AMaViS-user mailing list
AMaViS-user@lists.sourceforge.net 
https://lists.sourceforge.net/lists/listinfo/amavis-user 
 Please visit http://www.ijs.si/software/amavisd/ regularly
 For administrativa requests please send email to rainer at openantivirus dot 
org

Reply via email to