SA Bugzilla – Bug 5888
__VBOUNCE_AUTOMATIC generates FPs
Last modified: 2008-06-16 02:34:58 UTC
+++ This bug was initially created as a clone of Bug #5540 +++ The AutoReply string in __VBOUNCE_AUTOMATIC generates false positives against some legitimate "out of office" replies. Example: Subject: Out of Office AutoReply: <subject of original message> This check seems to be too generic for a virus bounce check.
OOO bounces are supposed to be detected by BOUNCE_MESSAGE -- I can see that that rule will fine with a VBOUNCE_MESSAGE hit as well. agreed, it shouldn't do that.
*** Bug 5540 has been marked as a duplicate of this bug. ***
looking at it now, I think that following rule shouldn't be put into VBOUNCE but into BOUNCE. header __VBOUNCE_AUTOMATIC Subject =~ /\b(automatic reply|AutoReply)\b/ I've seen many autoreplies containint either AutoReply or "automatic reply". If anyone receives much of real virus bounces, please comment
yes - I agree. if you feel like adding a patch to do that, I'd be very grateful ;)
Created attachment 4328 [details] moves the rule to the BOUNCE_MESSAGE section - commented out __VBOUNCE_AUTOMATIC - copied the rule definition as __BOUNCE_AUTO_REPLY - removed __VBOUNCE_AUTOMATIC from VBOUNCE_MESSAGE - added __BOUNCE_AUTO_REPLY to BOUNCE_MESSAGE
thanks! applied to trunk (with some changes since the ruleset is different there nowadays): : jm 11...; svn commit -m "bug 5888: remove __VBOUNCE_AUTOMATIC and move to BOUNCE_MESSAGE meta set -- 'automatic replies' are just bounces, not specifically virus-bounces. thanks to mouss for the fix" rules/20_vbounce.cf Sending rules/20_vbounce.cf Transmitting file data . Committed revision 668088. and updated the 3.2.x version with trunk's: : jm 13...; svn commit -m "bug 5888: remove __VBOUNCE_AUTOMATIC and move to BOUNCE_MESSAGE meta set -- 'automatic replies' are just bounces, not specifically virus-bounces. thanks to mouss for the fix. also bundle in all recent fixes to vbounce ruleset from trunk" rules/20_vbounce.cf Sending rules/20_vbounce.cf Transmitting file data . Committed revision 668089. and updates: svn commit -m "update VBounce ruleset in 3.2.x updates to match current trunk" /home/jm/ftp/sa/b3_2_0_updates/20_vbounce.cf Sending b3_2_0_updates/20_vbounce.cf Transmitting file data . Committed revision 668090.