Re: Configuration problem or false positive on STARTTLS injection test ?
Hanno Böck <[email protected]> Tue, 2 Jul 2024 13:29:47 +0200
| Newsgroups | gmane.mail.imap.courier.general |
|---|---|
| Message-ID | <[email protected]> |
Hi, I am one of the authors of that research paper. We have an overview of affected applications on our webpage at https://nostarttls.secvuln.info/ Two things to note: * While we could show an injection with courier and POP3 (which was already public in the bug tracker before), we were unable to come up with any attack scenario. This is due to the very limited capabilities of the POP3 protocol. This vulnerability is more severe in the case of IMAP or SMTP/Submission. * This was fixed in Courier 1.1.5. Therefore, if you are seeing this, you are likely using a rather old version of courier, and an update to a more recent version should fix the issue. -- Hanno Böck https://hboeck.de/ _______________________________________________ courier-users mailing list [email protected] Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users