Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-08-2011, 08:41 AM
Junior Member
 
Posts: 8
Default STARTTLS and Postfix

Hello folks!

As you may see postings from Wietse Venema - there are some issues with STARTTLS and Postfix:

US-CERT Vulnerability Note VU#555316
Plaintext command injection in multiple implementations of STARTTLS (CVE-2011-0411)


Now, on my systems I see this:

% telnet 0 25
220 myzimbra ESMTP Postfix
starttls
220 2.0.0 Ready to start TLS

% telnet 0 587
220 myzimbra ESMTP Postfix
starttls
220 2.0.0 Ready to start TLS


What is the best way to disable STARTTLS on Zimbra?


Thanks,
W.S.
Reply With Quote
  #2 (permalink)  
Old 03-09-2011, 07:08 AM
Junior Member
 
Posts: 8
Default

Hmmm...seems like this Postfix exploit is not a big thing...
Reply With Quote
  #3 (permalink)  
Old 04-21-2011, 11:26 AM
Junior Member
 
Posts: 7
Default

My Senior Sys. Admin. thinks it is a big deal and would like to know if there is a fix planned. Anyone have any ideas on this? He sent me to this link:

CVE - CVE-2011-0411 (under review)
Reply With Quote
  #4 (permalink)  
Old 04-23-2011, 07:18 AM
Elite Member
 
Posts: 303
Default

I'd suggest that you search the bugs page to see if there is a ticket open on it, if you don't find one, then open a ticket with the information that you've got.

Doug
__________________
Ben Franklin quote:

"Those who would give up Essential Liberty to purchase a little Temporary Safety, deserve neither Liberty nor Safety."
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.