Apache OpenOffice (AOO) Bugzilla – Issue 80675
mails with (certain) attachments are silently filtered
Last modified: 2007-10-31 19:20:04 UTC
Somebody today sent an email with an attached *.sxw (old OOo file format) to security-team@ooo. This mail did never arrive, nor did the sender get a notification that the mail would not be delivered. Totally unacceptable. In general, but in particular not for the security list, because we almost missed some information about possible security vulnerabilities.
Is this not a duplicate or similar to issue 78533 ?
Thank you for contacting CollabNet Customer Support. Based on the information that has been provided to us, we will initiate our research & provide you an update as soon as we have adequate information. Regards, Kavitha Support Operations
Hi Is this the only mail that didn't get delivered or are all the mails sent to this mailing list not getting delivered? Also, Can you please provide us the header info of the sent mail to the list? Yes, this sounds similar to the issue 78533 which is considered for future release as an enhancement request. ie. To have email notification if an attachment gets dropped. Regards Kavitha Support Operations
No, this is not releated to 78533. 78533 is about dropped ATTACHMENTS. This one is about NOT DELIVERED EMAILS. But I am not able to reproduce with random attachments, I will send you the email where the issue occurs.
Hi, Could you give us an update on this issue so that i can file an internal ticket. Regards, Abinav Support Operations.
I have no clue what kind of update you want. I have written everything above, and have send the email to jkavitha@openoffice.org Malte.
Hi Malte, I apologize for the delay in getting back to you on this. Meanwhile, i have forwarded this request internally to identify why e-mails with specific format are filtered out without notifying the sender of the mail upon posting it to the security list. It would also be supportive for this issue, if you could forward us the mails which skips the attachments when sent to the list. I Will follow up with the internal team to keep you posted on the progress. kind Regards, Vathsan Support Operations.
Hi Malte, Could you give us an approximate time at which the mail was sent(dropped) on 8/15, It would really help us determine what the problem is and is it okay if i subscribe to the security mailing list to send a test sxw file of my own. Also jkavitha@ooo did not receive the mail with the .sxw attachment could you please attach the file to this case. Regards, Abinav Support Operations.
I just resent to abinav_cn@openoffice.org and jkavitha@openoffice.org. I can't attach the doc because it has some content which is only for the people from the security list. Abinav - sure you can *temporarily* subscribe to the list to fix this, but please keep in mind that some information in mails on that list might be confidential.
I forgot to answer one question: The original mail was send 08/15 11:32 CEST. But I tried multiple times that day.
Hi Malte, Thank you for replying to my questions. I will *temporarily* subscribe to the security mailing list and send a few .sxw files of my own. Hopefully we should be able to get to the bottom of this and come up with a solution and i will use full discretion on any mails i receive from the security list. Regards, Abinav. Support Operations
Hi Malte, I sent an email to the security team mailing list with a .sxw and received it without any problems. I am pretty sure that you must have gotten a copy of that mail too, But i still am yet to receive the original mail that you have sent. I'll check with jkavitha and see if she has gotten the mail. Regards, Abinav Support Operations. P.S. I will unsubscribe from the mailing list in a day or two. i just need to try sending the original attachment to the list and see what happens.
Hi Malte, Could you provide us with the header information of the mail that you sent to me and jkavitha and the header information for the mail that contained the original attachment. Regards, Abinav Support Operations
Hi Malte, On analysis of the logs we found that there were no messages sent to security-team at 9:32 PDT (11:32 EST), In fact the only messages sent to security-team on 8/15 were at 02:28 and 23:45 which are archived. URL : http://www.openoffice.org/servlets/ReadMsg?list=security-team&msgNo=484 URL : http://www.openoffice.org/servlets/ReadMsg?list=security-team&msgNo=483 (Both test mails by you). starting delivery 1742451: msg 82014 to local httpd-security-team@openoffice.org delivery 1742451: success: ezmlm-reject:_fatal:_Sorry,_I_don't_accept_messages_of_MIME_Content- Type_'text/html'_(#5.2.3)/did_0+0+1/ This message was attempted to be sent 3 times in a row around 23:45, 23:49, and 23:52. you can read this man page for more information about how ezmlm-reject would reject an email based on mime type. URL : http://www.ezmlm.org/man/man1/ezmlm-reject.1.html Another thing that we noticed is that the allowed posters for this list has only 6 members, so it is also possible that the user who sent the email that got dropped was not on this list. Regards, Abinav Support Operations.
I am allowed to send mails, and that one still doesn't make it to the list. If I understand it correctly, even you didn't get it while being on cc? I will send again to you.
Hi Malte, I have still not received the original e mail. could you send the e mail out to abinav@collab.net or to jkavitha@collab.net. Regards, Abinav Support Operations.
Did just resend again. I think it's a more general issue with your mail server, please give me some other email address where I can send it to.
Hi Malte, How about abinavkris@gmail.com or abinav_kris@yahoo.co.in. Just send it to one of these email addresses. Once i get the attachment i think we can get to the bottom of why it is getting silently dropped. Regards Abinav Support Operations
Hi Malte, I was wondering if you had sent the attachment to one of the addresses i had given earlier. I am yet to receive the attachment. Regards, Abinav Support Operations
Sorry, I was on vacation. Done just now.
Updating whiteboard
MT , Thank you providing us the zip files , these files has been provided our internal team for investigation . The reasons why this particular file alone did not go through the list is really interesting and something to look into...
Malte, After our investigation we were able to identify the root cause of why this particular sxw file did not reach the list . It was due to our spam filter unable to scan attachments which has base64 coding . Note: As a policy we don't recommended to allow mail/mail attachments which cannot be scanned . However we have made an exception for this list , this is including another exception we had done previously for this list. Please do send the mail with the attachment once again and let us know if mail does reach the list successfully. Marking this issue as Fixed . Please verify and close this issue. Regards Jobin
Works for me :)
Close.