Source: gmime Version: 2.6.22-2 Severity: serious With package 'ripmime' installed:
------------------------------------------------------------ $ apt-get source gmime-bin $ cd gmime-2.6.22/tests/ $ mkdir attachments $ cd attachments $ cat ../message-partial.* ../*.eml |ripmime -i - $ ls -l *.jpg -rw------- 1 sliedes sliedes 115113 Mar 26 22:45 2377h003.jpg -rw------- 1 sliedes sliedes 17527 Mar 26 22:45 leonc.jpg -rw------- 1 sliedes sliedes 45064 Mar 26 22:45 SkipStone-Banner.jpg ------------------------------------------------------------ The file 2377h003.jpg is a photograph of a scantily clad model apparently taken by a pornographer named Suze Randall. The photograph, which "ripmime" unfortunately does not extract fully from the multipart message (you can build gmime and use tests/test-partial message-partial.* to combine the parts; the size should be 117415 bytes), contains the copyright notice "(c) 2001 Suze Randall" in the lower right corner. The file leonc.jpg is apparently part of a movie poster of the movie Leon: The Professional and depicts the character "Mathilda", a 12-year old girl played by Natalie Portman, with a huge gun in her hand. SkipStone-Banner appears to be a partial banner of an old web browser ("Gtk+ only browser"; I did not inspect what its license is, but did find a source download link). Sami -- System Information: Debian Release: 9.0 APT prefers unstable APT policy: (500, 'unstable'), (1, 'experimental') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 4.10.4 (SMP w/8 CPU cores; PREEMPT) Locale: LANG=en_US.UTF-8, LC_CTYPE=fi_FI.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system)
signature.asc
Description: PGP signature