Re: Configuration problem or false positive on STARTTLS injection test ?
Pascal Véron <[email protected]> Tue, 2 Jul 2024 15:08:47 +0200
| Newsgroups | gmane.mail.imap.courier.general |
|---|---|
| Message-ID | <[email protected]> |
Hi, Thank you for your work and these very useful informations. Older version we have is due to fact we are using Debian Courier packages. Always 1.0.16 https://packages.debian.org/bookworm/courier-mta Was hoping updates from maintainer but probably have to compil now Le 02/07/2024 à 13:29, Hanno Böck a écrit : > Hi, > > I am one of the authors of that research paper. > We have an overview of affected applications on our webpage > at https://nostarttls.secvuln.info/ > > Two things to note: > > * While we could show an injection with courier and POP3 (which was > already public in the bug tracker before), we were unable to come up > with any attack scenario. This is due to the very limited > capabilities of the POP3 protocol. This vulnerability is more severe > in the case of IMAP or SMTP/Submission. > > * This was fixed in Courier 1.1.5. Therefore, if you are seeing this, > you are likely using a rather old version of courier, and an update > to a more recent version should fix the issue. > > _______________________________________________ courier-users mailing list [email protected] Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users