BugTraq
[USN-74-1] Postfix vulnerability Feb 04 2005 09:13AM
Martin Pitt (martin pitt canonical com) (1 replies)
Re: [USN-74-1] Postfix vulnerability Feb 05 2005 10:09PM
wietse porcupine org (Wietse Venema)
FYI,

This is a bug in a third-party IPv6 patch that is not part of Postfix.

Neither the official Postfix release, nor the work-in-progress
version are not affected by this.

Wietse

Martin Pitt:
> Jean-Samuel Reynaud noticed a programming error in the IPv6 handling
> code of Postfix when /proc/net/if_inet6 is not available (which is the
> case in Ubuntu since Postfix runs in a chroot). If "permit_mx_backup"
> was enabled in the "smtpd_recipient_restrictions", Postfix turned into
> an open relay, i. e. erroneously permitted the delivery of arbitrary
> mail to any MX host which has an IPv6 address.

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus