From: Leonardo A. <rn...@gm...> - 2009-08-24 13:58:40
|
On Mon, Aug 24, 2009 at 3:19 PM, Mark Martinec<Mar...@ij...> wrote: > Leonardo, > >> I'm building a new machine to replace an aged amavis installation. >> So far the new machine is in "sending only" configuration (it does no >> receive mail yet). >> I've run successfully v2.6.3 with the $banned_filename_re set to: >> $banned_filename_re = new_RE( ... > >> This configuration allowed me to block executables within archives. >> >> Upgrading to v2.6.4, archives with executables files in them (.exe) >> are no longer blocked, and I dunno why. > > >> Aug 24 12:13:26 smtp amavis[20479]: (20479-01) Unzipping p003 > >> Aug 24 12:13:26 smtp amavis[20479]: (20479-01) (!)Decoding of p003 >> (Zip archive data, at least v2.0 to extract) failed, leaving it >> unpacked: Compress::Raw::Zlib version 2.017 required-- >> this is only version 2.008 at (eval 100) line 467. > >> Aug 24 12:13:26 smtp amavis[20479]: (20479-01) decompose_part: p003 - >> source retained > > As the message indicates, your Compress::Raw::Zlib is too old > and is not called for security reasons (DoS). > > Mark > Thanks! I didn't noticed it! :-) leo |