Re: Configuration problem or false positive on STARTTLS injection test ?

Hanno Böck <[email protected]> Tue, 2 Jul 2024 13:29:47 +0200
Newsgroups gmane.mail.imap.courier.general
Message-ID <[email protected]>
Hi,

I am one of the authors of that research paper.
We have an overview of affected applications on our webpage
at https://nostarttls.secvuln.info/

Two things to note:

* While we could show an injection with courier and POP3 (which was
  already public in the bug tracker before), we were unable to come up
  with any attack scenario. This is due to the very limited
  capabilities of the POP3 protocol. This vulnerability is more severe
  in the case of IMAP or SMTP/Submission.

* This was fixed in Courier 1.1.5. Therefore, if you are seeing this,
  you are likely using a rather old version of courier, and an update
  to a more recent version should fix the issue.


-- 
Hanno Böck
https://hboeck.de/


_______________________________________________
courier-users mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users