Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Postfix, a popular mail server, allowed SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3725-1
New postfix packages are available for Slackware 15.0 and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] postfix (SSA:2024-022-01) New postfix packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/postfix-3.6.14-i586-1_slack15.0.txz: Upgraded. Security (inbound SMTP smuggling): with "smtpd_forbid_bare_newline = normalize" (default "no" for Postfix < 3.9), the Postfix SMTP server requires the standard End-of-DATA sequence . , and otherwise allows command or message content lines ending in the non-standard , processing them as if the client sent the standard . The alternative setting, "smtpd_forbid_bare_newline = reject" will reject any command or message that contains a bare , and is more likely to cause problems with legitimate clients. For backwards compatibility, local clients are excluded by default with "smtpd_forbid_bare_newline_exclusions = $mynetworks". For more information, see: https://www.postfix.org/smtp-smuggling.html (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: 294738922ff08821267867f0bc877f20 postfix-3.6.14-i586-1_slack15.0.txz Slackware x86_64 15.0 package: e82bb102cc325850e48aca41f909e812 postfix-3.6.14-x86_64-1_slack15.0.txz Slackware -current package: 7e088581a14eb986f767bc08d9203103 n/postfix-3.8.5-i586-1.txz Slackwarex86_64 -current package: 50f7d14d0ddc0ce62e29cb55a2cffa31 n/postfix-3.8.5-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg postfix-3.6.14-i586-1_slack15.0.txz Restart the postfix server: # /etc/rc.d/rc.postfix restart +-----+ . Recent postfix updates for Slackware fix a major incoming SMTP vulnerability. Update immediately to safeguard your email server.. Postfix Security, Slackware Update, Mail Server Security, SMTP Fix, Package Management. . Severity: Important. LinuxSecurity.com Team
An update that fixes 7 vulnerabilities is now available. . openSUSE Security Update: Security update for exim ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0007-1 Rating: important References: #1218387 Cross-References: CVE-2022-3559 CVE-2023-42114 CVE-2023-42115 CVE-2023-42116 CVE-2023-42117 CVE-2023-42119 CVE-2023-51766 CVSS scores: CVE-2022-3559 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: This update for exim fixes the following issues: exim was updated to 4.97.1 (boo#1218387, CVE-2023-51766): * Fixes for the smtp protocol smuggling (CVE-2023-51766) exim was updated to exim 4.96: * Move from using the pcre library to pcre2. * Constification work in the filters module required a major version bump for the local-scan API. Specifically, the "headers_charset" global which is visible via the API is now const and may therefore not be modified by local-scan code. * Bug 2819: speed up command-line messages being read in. Previously a time check was being done for every character; replace that with one per buffer. * Bug 2815: Fix ALPN sent by server under OpenSSL. Previously the string sent was prefixed with a length byte. * Change the SMTP feature name for pipelining connect to be compliant with RFC 5321. Previously Dovecot (at least) would log errors during submission. * Fix macro-definition during "-be" expansion testing. The move to write-protected store for macros had not accounted for these runtime additions; fix by removing this protection for "-be" mode. * Convert all uses of select() topoll(). * Fix use of $sender_host_name in daemon process. When used in certain main-section options or in a connect ACL, the value from the first ever connection was never replaced for subsequent connections. * Bug 2838: Fix for i32lp64 hard-align platforms * Bug 2845: Fix handling of tls_require_ciphers for OpenSSL when a value with underbars is given. * Bug 1895: TLS: Deprecate RFC 5114 Diffie-Hellman parameters. * Debugging initiated by an ACL control now continues through into routing and transport processes. * The "expand" debug selector now gives more detail, specifically on the result of expansion operators and items. * Bug 2751: Fix include_directory in redirect routers. Previously a bad comparison between the option value and the name of the file to be included was done, and a mismatch was wrongly identified. * Support for Berkeley DB versions 1 and 2 is withdrawn. * When built with NDBM for hints DB's check for nonexistence of a name supplied as the db file-pair basename. * Remove the "allow_insecure_tainted_data" main config option and the "taint" log_selector. * Fix static address-list lookups to properly return the matched item. Previously only the domain part was returned. * The ${run} expansion item now expands its command string elements after splitting. Previously it was before; the new ordering makes handling zero-length arguments simpler. * Taint-check exec arguments for transport-initiated external processes. Previously, tainted values could be used. This affects "pipe", "lmtp" and "queryprogram" transport, transport-filter, and ETRN commands. The ${run} expansion is also affected: in "preexpand" mode no part of the command line may be tainted, in default mode the executable name may not be tainted. * Fix CHUNKING on a continued-transport. Previously the usabilility of the facility was notpassed across execs, and only the first message passed over a connection could use BDAT; any further ones using DATA. * Support the PIPECONNECT facility in the smtp transport when the helo_data uses $sending_ip_address and an interface is specified. * OpenSSL: fix transport-required OCSP stapling verification under session resumption. * TLS resumption: the key for session lookup in the client now includes more info that a server could potentially use in configuring a TLS session, avoiding oferring mismatching sessions to such a server. * Fix string_copyn() for limit greater than actual string length. * Bug 2886: GnuTLS: Do not free the cached creds on transport connection close; it may be needed for a subsequent connection. * Fix CHUNKING for a second message on a connection when the first was rejected. * Fix ${srs_encode ...} to handle an empty sender address, now returning an empty address. * Bug 2855: Handle a v4mapped sender address given us by a frontending proxy. update to exim 4.95 * includes taintwarn (taintwarn.patch) * fast-ramp queue run * native SRS * TLS resumption * LMDB lookups with single key * smtp transport option "message_linelength_limit" * optionally ignore lookup caches * quota checking for appendfile transport during message reception * sqlite lookups allow a "file= " option * lsearch lookups allow a "ret=full" option * command line option for the notifier socket * faster TLS startup * new main config option "proxy_protocol_timeout" * expand "smtp_accept_max_per_connection" * log selector "queue_size_exclusive" * main config option "smtp_backlog_monitor" * main config option "hosts_require_helo" * main config option "allow_insecure_tainted_data" Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypperpatch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-7=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 ppc64le s390x x86_64): exim-4.97.1-bp155.5.9.1 eximon-4.97.1-bp155.5.9.1 eximstats-html-4.97.1-bp155.5.9.1 References: https://www.suse.com/security/cve/CVE-2022-3559.html https://www.suse.com/security/cve/CVE-2023-42114.html https://www.suse.com/security/cve/CVE-2023-42115.html https://www.suse.com/security/cve/CVE-2023-42116.html https://www.suse.com/security/cve/CVE-2023-42117.html https://www.suse.com/security/cve/CVE-2023-42119.html https://www.suse.com/security/cve/CVE-2023-51766.html https://bugzilla.suse.com/1218387 . An important update for openSUSE addresses multiple exim security issues and fixes 7 vulnerabilities.. openSUSE, exim, security patch, smtp update, important advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for evolution-data-server ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0885-1 Rating: moderate References: #1173910 #1174712 #1182882 Cross-References: CVE-2020-14928 CVE-2020-16117 CVSS scores: CVE-2020-14928 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2020-14928 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2020-16117 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-16117 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP5 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for evolution-data-server fixes the following issues: - Fix buffer overrun when parsing base64 data (bsc#1182882). - CVE-2020-16117: Fix crash on malformed server response with minimal capabilities (bsc#1174712). - CVE-2020-14928: Response injection via STARTTLS in SMTP and POP3 (bsc#1173910). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2021-885=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): libcamel-1_2-57-3.20.6-17.3.1 libcamel-1_2-57-debuginfo-3.20.6-17.3.1 libedataserver-1_2-21-3.20.6-17.3.1 libedataserver-1_2-21-debuginfo-3.20.6-17.3.1 References: https://www.suse.com/security/cve/CVE-2020-14928.html https://www.suse.com/security/cve/CVE-2020-16117.html https://bugzilla.suse.com/1173910 https://bugzilla.suse.com/1174712 https://bugzilla.suse.com/1182882 . A recent security patch resolves vulnerabilities in evolution-data-server, tackling concerns such as buffer overflow and injection vulnerabilities in responses.. SUSE Linux, evolution-data-server, Security Update, System Patch Management. . LinuxSecurity.com Team
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable (CVE-2020-26970). . MGASA-2020-0450 - Updated thunderbird packages fix security vulnerability Publication date: 05 Dec 2020 URL: https://advisories.mageia.org/MGASA-2020-0450.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-26970 When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable (CVE-2020-26970). References: - https://bugs.mageia.org/show_bug.cgi?id=27707 - https://www.mozilla.org/en-US/security/advisories/mfsa2020-53/ - https://www.thunderbird.net/en-US/thunderbird/78.5.1/releasenotes/ - https://www.cve.org/CVERecord?id=CVE-2020-26970 SRPMS: - 7/core/thunderbird-78.5.1-1.mga7 - 7/core/thunderbird-l10n-78.5.1-1.mga7 - 7/core/rootcerts-20201201.00-1.mga7 . New Thunderbird updates address a severe stack overflow vulnerability, presenting security concerns for its users.. Thunderbird Update, Mageia Security, Stack Corruption, Software Exploit, SMTP Issue. . Severity: Critical. LinuxSecurity.com Team
Updated postfix packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: postfix security update Advisory ID: RHSA-2011:0423-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:0423.html Issue date: 2011-04-06 CVE Names: CVE-2011-0411 ==================================================================== 1. Summary: Updated postfix packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL), and TLS. It was discovered that Postfix did not flush the received SMTP commands buffer after switching to TLS encryption for an SMTP session. A man-in-the-middle attacker could use this flaw to inject SMTP commands into a victim's session during the plain text phase. This would lead to those commands being processed by Postfix after TLS encryption is enabled, possibly allowing the attacker to stealthe victim's mail or authentication credentials. (CVE-2011-0411) Red Hat would like to thank the CERT/CC for reporting CVE-2011-0411. The CERT/CC acknowledges Wietse Venema as the original reporter. Users of Postfix are advised to upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing this update, the postfix service will be restarted automatically. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 674814 - CVE-2011-0411 postfix: SMTP commands injection during plaintext to TLS session switch 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: i386: postfix-2.6.6-2.1.el6_0.i686.rpm postfix-debuginfo-2.6.6-2.1.el6_0.i686.rpm x86_64: postfix-2.6.6-2.1.el6_0.x86_64.rpm postfix-debuginfo-2.6.6-2.1.el6_0.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: postfix-debuginfo-2.6.6-2.1.el6_0.i686.rpm postfix-perl-scripts-2.6.6-2.1.el6_0.i686.rpm x86_64: postfix-debuginfo-2.6.6-2.1.el6_0.x86_64.rpm postfix-perl-scripts-2.6.6-2.1.el6_0.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: postfix-2.6.6-2.1.el6_0.x86_64.rpm postfix-debuginfo-2.6.6-2.1.el6_0.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: postfix-debuginfo-2.6.6-2.1.el6_0.x86_64.rpm postfix-perl-scripts-2.6.6-2.1.el6_0.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: i386: postfix-2.6.6-2.1.el6_0.i686.rpm postfix-debuginfo-2.6.6-2.1.el6_0.i686.rpm ppc64: postfix-2.6.6-2.1.el6_0.ppc64.rpm postfix-debuginfo-2.6.6-2.1.el6_0.ppc64.rpm s390x: postfix-2.6.6-2.1.el6_0.s390x.rpm postfix-debuginfo-2.6.6-2.1.el6_0.s390x.rpm x86_64: postfix-2.6.6-2.1.el6_0.x86_64.rpm postfix-debuginfo-2.6.6-2.1.el6_0.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: i386: postfix-debuginfo-2.6.6-2.1.el6_0.i686.rpm postfix-perl-scripts-2.6.6-2.1.el6_0.i686.rpm ppc64: postfix-debuginfo-2.6.6-2.1.el6_0.ppc64.rpm postfix-perl-scripts-2.6.6-2.1.el6_0.ppc64.rpm s390x: postfix-debuginfo-2.6.6-2.1.el6_0.s390x.rpm postfix-perl-scripts-2.6.6-2.1.el6_0.s390x.rpm x86_64: postfix-debuginfo-2.6.6-2.1.el6_0.x86_64.rpm postfix-perl-scripts-2.6.6-2.1.el6_0.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: i386: postfix-2.6.6-2.1.el6_0.i686.rpm postfix-debuginfo-2.6.6-2.1.el6_0.i686.rpm x86_64: postfix-2.6.6-2.1.el6_0.x86_64.rpm postfix-debuginfo-2.6.6-2.1.el6_0.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: postfix-debuginfo-2.6.6-2.1.el6_0.i686.rpm postfix-perl-scripts-2.6.6-2.1.el6_0.i686.rpm x86_64: postfix-debuginfo-2.6.6-2.1.el6_0.x86_64.rpm postfix-perl-scripts-2.6.6-2.1.el6_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2011-0411 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2011 Red Hat, Inc. . Red Hat's recent security advisory details crucial updates for Postfix, fixing vulnerabilities including improper TLS handling that risk data integrity and expose systems.. Postfix Security, Red Hat Advisory, SMTP Update, TLS Issue, Mail Transport Agent. .LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.