Re: CVE-2019-19521 what about OpenSMTPD ?

2019-12-05 Thread Francisco de Borja Lopez Rio
Hi. Thanks a lot for taking the time to write about this Gilles. Regards. On Thu, Dec 05, 2019 at 07:59:28AM +0100, Gilles Chehade wrote: > Hello, > > In case you haven't seen, multiple CVE were released by Qualys: > > https://www.openwall.com/lists/oss-security/2019/12/04/5 > > CVE-2019-195

CVE-2019-19521 what about OpenSMTPD ?

2019-12-04 Thread Gilles Chehade
Hello, In case you haven't seen, multiple CVE were released by Qualys: https://www.openwall.com/lists/oss-security/2019/12/04/5 CVE-2019-19521 refers to an Authentication bypass allowing remote people to authenticate to an OpenSMTPD without credentials. A few people were wondering why we di