On 10 May 2014 08:40:53 CEST, Alexander Wirt <[email protected]> wrote: >On Fri, 25 Apr 2014, Daniel Pocock wrote: > >> Package: amavis-new >> Version: 1:2.7.1-2 >> Severity: serious >> >> >> When an email is banned due to an attachment, the ban email sent to >the >> sender includes the ultimate recipient's address resolved by the >virtual >> lookup table >> >> This appears to be a privacy risk, as the virtual mapping contains >email >> addresses that may not already be known to the sender. >No, you should never send those mails to someone out of your domain. If >you >don't want to expose this, don't send this mails. > >This is entirely configurable and there is no useful option for amavis >to >prevent this problem. Therefore I'll close this bug. > >If you disagree feel free to reopen the bug, but imho this is a user >configuration problem and no software problem. >
It is a default config using the config files from the package Therefore it is likely other users will end up observing the same problem. I would prefer to pinpoint what causes this rather than closing the bug without any analysis -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected]

