On 06/12/17 16:12, Adrian Zaugg wrote:
> The mailsploit attack relies on special chars like newline or the nul
> character encoded in base64 or quoted-printable. In my opinion encoded
> strings in mail headers should get decoded for validity checking, e.g
> when setting in an ACL: require verify = headers_syntax
> Am I wrong with this assumption?

RFC 5322 says nothing about encoding.
-- 
Cheers,
  Jeremy

-- 
## List details at https://lists.exim.org/mailman/listinfo/exim-users
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
  • ... Adrian Zaugg
    • ... Jeremy Harris
    • ... Viktor Dukhovni
      • ... Adrian Zaugg
        • ... =?utf-8?B?0JLQuNC60YLQvtGAINCU0YPRhdC+0LLQvdGL0LkgPGV4aW0tdXNlcnNAZHVraG92?= =?utf-8?B?bmkub3JnPiwgQWxzbyBLbm93biBBcyBWaWt0b3IgRHVraG92bmkgPGV4aW0tdXNl?= =?utf-8?B?cnNAZHVraG92bmkub3JnPgo=?=
          • ... Mike Brudenell via Exim-users
            • ... Dennis Davis via Exim-users
              • ... Viktor Dukhovni
        • ... Виктор Духовный

Reply via email to