#62 Reject multi-valued From messages

1.1.3
open
nobody
None
2014-08-01
2014-01-02
No

While multiple From: header in an email is not allowed, a multi-valued from header is. However practically it is not used. It has been sighted mainly in bounces and in an old version of .NET but this reflects more poor configuration or bug than something mean to be. Rejecting a multi-valued from header would avoid:
-Algorithm complexity
-Reduce a potential attack vector

This option should be off by default and not recommended.

Discussion

  • Murray S. Kucherawy

    • summary: reject multi-valued From messages --> Reject multi-valued From messages
     
  • Murray S. Kucherawy

    Likely needs to wait for a later release since the From: parser can only handle single-value fields at the moment. Will need to tie in to libopendmarc since it has the OD stuff in it already.

     
  • Murray S. Kucherawy

    • Target: 1.0.0 --> 1.1.3
     
  • Murray S. Kucherawy

    Planned for next major release.

     

Get latest updates about Open Source Projects, Conferences and News.

Sign up for the SourceForge newsletter:





No, thanks