|
Family: Ubuntu Local Security Checks --> Category: infos
USN74-1 : postfix vulnerability Vulnerability Scan
Vulnerability Scan Summary postfix vulnerability
Detailed Explanation for this Vulnerability Test
Synopsis :
These remote packages are missing security patches :
- postfix
- postfix-dev
- postfix-doc
- postfix-ldap
- postfix-mysql
- postfix-pcre
- postfix-pgsql
- postfix-tls
Description :
Jean-Samuel Reynaud noticed a programming error in the IPv6 handling
code of Postfix when /proc/net/if_inet6 is not available (which is the
case in Ubuntu since Postfix runs in a chroot). If "permit_mx_backup"
was enabled in the "smtpd_recipient_restrictions", Postfix turned into
an open relay, i. e. erroneously permitted the delivery of arbitrary
mail to any MX host which has an IPv6 address.
Solution :
Upgrade to :
- postfix-2.1.3-1ubuntu17.1 (Ubuntu 4.10)
- postfix-dev-2.1.3-1ubuntu17.1 (Ubuntu 4.10)
- postfix-doc-2.1.3-1ubuntu17.1 (Ubuntu 4.10)
- postfix-ldap-2.1.3-1ubuntu17.1 (Ubuntu 4.10)
- postfix-mysql-2.1.3-1ubuntu17.1 (Ubuntu 4.10)
- postfix-pcre-2.1.3-1ubuntu17.1 (Ubuntu 4.10)
- postfix-pgsql-2.1.3-1ubuntu17.1 (Ubuntu 4.10)
- postfix-tls-2.1.3-1ubuntu17.1 (Ubuntu 4.10)
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|