[Pkg-mailman-hackers] Bug#342645: Mailman: header sanitizing

Adrian von Bidder avbidder at fortytwo.ch
Fri Dec 9 08:52:36 UTC 2005


Package: mailman
Version: 2.1.5-8

Yo!

The MIME parser mailman seems to do some header sanitizing, at least for 
message/rfc822 attachments.  This is problematic as it breaks the PGP 
signature on the mail:

My case: mail was 
  multipart/signed [ text/plain message/rfc822 [
      multipart/signed [ text/plain application/pgp-signature ] 
  ] ]

when it was fed to mailman.  mailman of course wrapps that in 
multipart/mixed to add the unsubscribe instructions, and additionally 
breaks long header lines of the inner message/rfc822 (IIRC the outer 
headers where similarly sanitized, but as they're not signed it doesn't 
matter.)

mailman has been identified as the culprit imho - I've sent a mail with the 
same structure over the same server, but directly to an account instead of 
mailman, and the signature arrived intact.

greetings
-- vbi


-- 
get my gpg key here: http://fortytwo.ch/gpg/92082481
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 388 bytes
Desc: not available
Url : http://lists.alioth.debian.org/pipermail/pkg-mailman-hackers/attachments/20051209/00d84095/attachment.pgp


More information about the Pkg-mailman-hackers mailing list