Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 528
Alerts This Week
Warning Icon 1 528

Ubuntu 11.04: USN-1132-1 Severe Postfix Service Interruption

ubuntu
Calendar Grey May 11, 2011
Scroller Ubuntu
A vulnerability impacts various Ubuntu versions stemming from a Postfix defect that enables malicious users to destabilize the system or run arbitrary code.
An attacker could send crafted input to Postfix and cause it to crash or run programs.

Summary

An attacker could send crafted input to Postfix and cause it to crash or

run programs.

Software Description:

- postfix: High-performance mail transport agent

Details:

Thomas Jarosch discovered that Postfix incorrectly handled authentication

mechanisms other than PLAIN and LOGIN when the Cyrus SASL library is used.

A remote attacker could use this to cause Postfix to crash, leading to a

denial of service, or possibly execute arbitrary code as the postfix user.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  postfix                         2.8.2-1ubuntu2.1

Ubuntu 10.10:
  postfix                         2.7.1-1ubuntu0.2

Ubuntu 10.04 LTS:
  postfix                         2.7.0-1ubuntu0.2

Ubuntu 8.04 LTS:
  postfix                         2.5.1-2ubuntu1.4

Ubuntu 6.06 LTS:
  postfix                         2.2.10-1ubuntu0.4

In general, a standard system update will make all the necessary changes.

References

CVE-2011-1720

Severity
critical
Lowest
Low
Medium
High
Critical

May 11, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.