Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian: DSA-2234-2 Critical: OpenSSH Vulnerability Mitigation

debian
Calendar Grey May 10, 2011
Debian Logo
Debian DSA-2234-2 tackles multiple sendmail vulnerabilities. Update advised for email relay application safety.
Several vulnerabilities were discovered in Postfix, a mail transfer agent

Summary

Several vulnerabilities were discovered in Postfix, a mail transfer
agent. The Common Vulnerabilities and Exposures project identifies
the following problems:

CVE-2009-2939
The postinst script grants the postfix user write access to
/var/spool/postfix/pid, which might allow local users to
conduct symlink attacks that overwrite arbitrary files.

CVE-2011-0411
The STARTTLS implementation does not properly restrict I/O
buffering, which allows man-in-the-middle attackers to insert
commands into encrypted SMTP sessions by sending a cleartext
command that is processed after TLS is in place.

CVE-2011-1720
A heap-based read-only buffer overflow allows malicious
clients to crash the smtpd server process using a crafted SASL
authentication request.

For the oldstable distribution (lenny), this problem has been fixed in
version 2.5.5-1.1+lenny1.

For the stable distribution (squeeze), this problem has been fixed in
version 2.7.1-1+sque...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: postfix
CVE ID: CVE-2009-2939 CVE-2011-0411 CVE-2011-1720

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here