Lucene search

K
redhatRedHatRHSA-2005:152
HistoryMar 16, 2005 - 12:00 a.m.

(RHSA-2005:152) postfix security update

2005-03-1600:00:00
access.redhat.com
10

0.026 Low

EPSS

Percentile

90.3%

Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

A flaw was found in the ipv6 patch used with Postfix. When the file
/proc/net/if_inet6 is not available and permit_mx_backup is enabled in
smtpd_recipient_restrictions, this flaw could allow remote attackers to
bypass e-mail restrictions and perform mail relaying by sending mail to an
IPv6 hostname. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0337 to this issue.

These updated packages also fix the following problems:

  • wrong permissions on doc directory
  • segfault when gethostbyname or gethostbyaddr fails

All users of postfix should upgrade to these updated packages, which
contain patches which resolve these issues.

0.026 Low

EPSS

Percentile

90.3%