[Users] [Bug 3457] broken winmail.dat attachments cause crash

noreply at thewildbeast.co.uk noreply at thewildbeast.co.uk
Sat Jul 4 10:39:32 CEST 2015


http://www.thewildbeast.co.uk/claws-mail/bugzilla/show_bug.cgi?id=3457

--- Comment #7 from Andrej Kacian <andrej at kacian.sk> ---
I took a look at the TNEF parsing code, and unfortunately, the code we have
from libytnef is apparently written by someone who does not believe in
possibility of people sending malformed data.

I tried to add in some checks to prevent crashing, but after a bit of time, I
realized I would have to overhaul the entire code, and I do not really have
time nor motivation to do that.

At this point, I wonder if dropping the tnef_parse plugin wouldn't be a better
idea, since I can't rule out a possibility of a security hole, via a
specifically crafted attachment. Instead of a crash, your computer might get
compromised.

-- 
You are receiving this mail because:
You are the assignee for the bug.



More information about the Users mailing list