Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Fri, 22 Dec 2023 17:41:56 +0100
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Fwd: [pfx-ann] Postfix stable release 3.8.4

----- Forwarded message from Wietse Venema via Postfix-announce <postfix-announce@...tfix.org> -----

To: Postfix announce <postfix-announce@...tfix.org>
Date: Fri, 22 Dec 2023 11:30:21 -0500 (EST)
CC: Postfix users <postfix-users@...tfix.org>
Subject: [pfx-ann] Postfix stable release 3.8.4
From: Wietse Venema via Postfix-announce <postfix-announce@...tfix.org>
Reply-To: Wietse Venema <wietse@...cupine.org>

[An on-line version of this announcement will be available at https://www.postfix.org/announcements/postfix-3.8.4.html]

Fixed with Postfix 3.8.4:

  * Security: this release adds support to defend
    against an email spoofing attack (SMTP smuggling) on
    recipients at a Postfix server. For background, see
    https://www.postfix.org/smtp-smuggling.html.

    Sites concerned about SMTP smuggling attacks should enable this
    feature on Internet-facing Postfix servers. For compatibility
    with non-standard clients, Postfix by default excludes clients
    in mynetworks from this countermeasure.

    The recommended settings are:

	# Optionally disconnect remote SMTP clients that send bare newlines,
	# but allow local clients with non-standard SMTP implementations
	# such as netcat, fax machines, or load balancer health checks.
	#
	smtpd_forbid_bare_newline = yes
	smtpd_forbid_bare_newline_exclusions = $mynetworks

    The smtpd_forbid_bare_newline feature is disabled by default.

You can find the updated Postfix source code at the mirrors listed at
https://www.postfix.org/.

	Wietse
_______________________________________________
Postfix-announce mailing list -- postfix-announce@...tfix.org
To unsubscribe send an email to postfix-announce-leave@...tfix.org

----- End forwarded message -----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.