We do not have the Sophos Mail protection component just the Network Security licensed. Last night I noticed we we're getting a lot of "attacks" on our mail server the the UTM aperently blocked. The Sig's are:
22115 SERVER-MAIL Metamail header length exploit attempt
22114 SERVER-MAIL Metamail header length exploit attempt
22111 SERVER-MAIL Metamail format string exploit attempt
22113 SERVER-MAIL Metamail header length exploit attempt
The hosts listed are generally trusted server or companies that we do a lot of business with.
Today we are getting complaints that certain Emails are not coming through where others are. I can imagine that this is the reason so I made a rule that disabled the SMTP intrusion prevention.
Is this a known issue? Are all UTM users having the same issue yesterday and today?
This thread was automatically locked due to age.