Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Courier-MTA spf.c DoS vuln - fixed?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
dephzon
n00b
n00b


Joined: 27 Nov 2003
Posts: 7

PostPosted: Thu Jul 07, 2005 11:57 am    Post subject: Courier-MTA spf.c DoS vuln - fixed? Reply with quote

Hi!

Did I miss it - or isn't there an patch available for the actual courier instance in portage?

The actual courier instance in portage has IMHO an DoS vulnerability in spf.c.

my courier says:

hostname ~ # courier --version
Courier 0.48.1 Copyright 1999-2004 Double Precision, Inc.

The actual fixed version is - AFAIK 0.50.1. I think it is not that critical - I am just not sure wether this issue is fixed or not - anyone knows?

EDIT: Advisory here: http://secunia.com/advisories/15901/

bye
dephzon
Back to top
View user's profile Send private message
kashani
Advocate
Advocate


Joined: 02 Sep 2002
Posts: 2032
Location: San Francisco

PostPosted: Thu Jul 07, 2005 3:44 pm    Post subject: Reply with quote

Hmmm 0.50.1 isn't in portage yet and 0.50.0 is still masked. It looks like you'll need to either disable SPF which should be off by default according to the Courier docs or try to add this patch to 0.48.1 or 0.50.0. That might not be easy.

http://sourceforge.net/mailarchive/forum.php?thread_id=7643256&forum_id=6705

There appear to be some work on the bug in bugzilla.
https://bugs.gentoo.org/show_bug.cgi?id=97915

kashani
_________________
Will personally fix your server in exchange for motorcycle related shop tools in good shape.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum