Postfix: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201206-33 / Postfix |
| Release Date |
June 25, 2012 |
| Latest Revision |
June 25, 2012: 1 |
| Impact |
high |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| mail-mta/postfix |
<
2.7.4 |
>=
2.7.4 |
All supported architectures
|
Related bugreports:
#358085, #366605
Synopsis
A vulnerability has been found in Postfix, the worst of which
possibly allowing remote code execution.
2.
Impact Information
Background
Postfix is Wietse Venema’s mailer that attempts to be fast, easy to
administer, and secure, as an alternative to the widely-used Sendmail
program.
Description
A vulnerability have been discovered in Postfix. Please review the CVE
identifier referenced below for details.
Impact
An attacker could perform a man-in-the-middle attack and inject SMTP
commands during the plaintext to TLS session switch or might execute
arbitrary code.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Postfix users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-mta/postfix-2.7.4"
|
4.
References
|