Package: courier-mta
Version: 0.75.0-18
Severity: grave
Justification: renders package unusable

Recently I decided to upgrade courier (mta and imap) on one of my mail servers. 
It was a disaster. The quality of these packages is abysmal and dangerous. This 
is one of the many serious, grave, and critical bugs I ran into during that 
process.



The following init script is broken:

/etc/init.d/courier-mta

The offening line is:

DO_START=$(sed -ne 's/^ESMTPDSSLSTART=\([^[:space:]]*\)/\1/p' 
/etc/courier/esmtpd-msa | tr "A-Z" "a-z")

This is the wrong configuration statement and file. The result will be either a 
broken system or worse an insecure system where a daemon is running when it 
should not be.

Corrected:

DO_START=$(sed -ne 's/^ESMTPDSTART=\([^[:space:]]*\)/\1/p' /etc/courier/esmtpd 
| tr "A-Z" "a-z")




-- System Information:
Debian Release: stretch/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.3.0-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)

Versions of packages courier-mta depends on:
ii  courier-authlib        0.66.4-7
ii  courier-base           0.75.0-18
ii  debconf [debconf-2.0]  1.5.59
ii  libc6                  2.22-7
ii  libcourier-unicode1    1.4-2
ii  libgcc1                1:5.3.1-14
ii  libgdbm3               1.8.3-13.1
ii  libidn11               1.32-3
ii  libnet-cidr-perl       0.17-1
ii  libperl5.22            5.22.1-10
ii  libstdc++6             5.3.1-14
ii  sysvinit-utils         2.88dsf-59.3

courier-mta recommends no packages.

Versions of packages courier-mta suggests:
ii  bsd-mailx [mail-reader]  8.1.2-0.20160123cvs-2
ii  courier-doc              0.75.0-18
ii  courier-filter-perl      0.200+ds-4
pn  couriergrey              <none>
ii  emacs24 [mail-reader]    24.5+1-6+b2
ii  mutt [mail-reader]       1.5.24-1+b1
ii  s-nail [mail-reader]     14.8.8-1

-- Configuration Files:
/etc/courier/aliases/system [Errno 13] Permission denied: 
u'/etc/courier/aliases/system'
/etc/courier/courierd changed [not included]
/etc/courier/dsnheader.txt changed [not included]
/etc/courier/esmtpauthclient [Errno 13] Permission denied: 
u'/etc/courier/esmtpauthclient'
/etc/courier/esmtpd changed [not included]
/etc/courier/esmtpd-msa changed [not included]
/etc/courier/esmtpd-ssl changed [not included]
/etc/courier/esmtpd.cnf [Errno 13] Permission denied: u'/etc/courier/esmtpd.cnf'
/etc/courier/smtpaccess/default [Errno 13] Permission denied: 
u'/etc/courier/smtpaccess/default'
/etc/init.d/courier-mta changed [not included]
/etc/init.d/courier-mta-ssl changed [not included]

-- debconf information excluded

Reply via email to