On 10 May 2014 08:40:53 CEST, Alexander Wirt <[email protected]> wrote:
>On Fri, 25 Apr 2014, Daniel Pocock wrote:
>
>> Package: amavis-new
>> Version: 1:2.7.1-2
>> Severity: serious
>> 
>> 
>> When an email is banned due to an attachment, the ban email sent to
>the
>> sender includes the ultimate recipient's address resolved by the
>virtual
>> lookup table
>> 
>> This appears to be a privacy risk, as the virtual mapping contains
>email
>> addresses that may not already be known to the sender.
>No, you should never send those mails to someone out of your domain. If
>you
>don't want to expose this, don't send this mails.
>
>This is entirely configurable and there is no useful option for amavis
>to
>prevent this problem. Therefore I'll close this bug.
>
>If you disagree feel free to reopen the bug, but imho this is a user
>configuration problem and no software problem.
>

It is a default config using the config files from the package

Therefore it is likely other users will end up observing the same problem.  I 
would prefer to pinpoint what causes this rather than closing the bug without 
any analysis


-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to