Multiple vulnerabilities in PostSRSd could lead to a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: PostSRSd: Denial of service Date: July 06, 2021 Bugs: #760821, #793674 ID: 202107-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in PostSRSd could lead to a Denial of Service condition. Background ========= PostSRSd is a Postfix sender rewriting scheme daemon Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-filter/postsrsd < 1.11 > = 1.11 Description ========== Multiple vulnerabilities have been discovered in PostSRSd. Please review the CVE identifiers referenced below for details. Impact ===== An attacker could cause a possible Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All postsrsd users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-filter/postsrsd-1.11" References ========= [ 1 ] CVE-2020-35573 https://nvd.nist.gov/vuln/detail/CVE-2020-35573 [ 2 ] CVE-2021-35525 https://nvd.nist.gov/vuln/detail/CVE-2021-35525 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202107-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and securityof our users' machines is of utmost importance to us. Any security concerns should be addressed to
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for postsrsd ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0669-1 Rating: moderate References: #1180251 Cross-References: CVE-2020-35573 Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for postsrsd fixes the following issues: Update to release 1.11 [boo#1180251] * Drop group privileges as well as user privileges * Fixed: The subprocess that talks to Postfix could be caused to hang with a very long email address. [CVE-2020-35573] Update to release 1.6 * Fix endianness issue with SHA-1 implementation * Add dual stack support * Make SRS separator configurable This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-669=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): postsrsd-1.11-bp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-35573.html https://bugzilla.suse.com/1180251 . This Fedora Security Patch targets a low impact vulnerability in postfix, improving overall performance.. postsrsd Update, openSUSE Security, Vulnerability Fix, Software Patch. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for postsrsd ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0646-1 Rating: moderate References: #1180251 Cross-References: CVE-2020-35573 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for postsrsd fixes the following issues: Update to release 1.11 [boo#1180251] * Drop group privileges as well as user privileges * Fixed: The subprocess that talks to Postfix could be caused to hang with a very long email address. [CVE-2020-35573] Update to release 1.6 * Fix endianness issue with SHA-1 implementation * Add dual stack support * Make SRS separator configurable Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-646=1 Package List: - openSUSE Leap 15.2 (x86_64): postsrsd-1.11-lp152.4.3.1 postsrsd-debuginfo-1.11-lp152.4.3.1 postsrsd-debugsource-1.11-lp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-35573.html https://bugzilla.suse.com/1180251 . A security update addressing one vulnerability in openSUSE's postsrsd has been issued. For further information, please consult the announcement ID.. openSUSE Security, postsrsd Update, Email Security Patch. . LinuxSecurity.com Team
A potential denial-of-service attack through malicious timestamp tags was fixed in PostSRSd, a Sender Rewriting Scheme (SRS) lookup table for Postfix. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2502-1
Get the latest Linux and open source security news straight to your inbox.