Re: Configuration problem or false positive on STARTTLS injection test ?

Pascal Véron <[email protected]> Tue, 2 Jul 2024 15:08:47 +0200
Newsgroups gmane.mail.imap.courier.general
Message-ID <[email protected]>
Hi,

Thank you for your work and these very useful informations.

Older version we have is due to fact we are using Debian Courier packages.

Always 1.0.16
https://packages.debian.org/bookworm/courier-mta

Was hoping updates from maintainer but probably have to compil now


Le 02/07/2024 à 13:29, Hanno Böck a écrit :
> Hi,
>
> I am one of the authors of that research paper.
> We have an overview of affected applications on our webpage
> at https://nostarttls.secvuln.info/
>
> Two things to note:
>
> * While we could show an injection with courier and POP3 (which was
>    already public in the bug tracker before), we were unable to come up
>    with any attack scenario. This is due to the very limited
>    capabilities of the POP3 protocol. This vulnerability is more severe
>    in the case of IMAP or SMTP/Submission.
>
> * This was fixed in Courier 1.1.5. Therefore, if you are seeing this,
>    you are likely using a rather old version of courier, and an update
>    to a more recent version should fix the issue.
>
>


_______________________________________________
courier-users mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users