Postfix is an attempt to provide an alternative to the widely-used Sendmail program. Postfix attempts to be fast, easy to administer, and hopefully secure, while at the same time being sendmail compatible enough to not upset your users.


2011-06-15 19:59

这个版本包含了CVE - 2011 - 1720,这会影响Postfix的SMTP服务器配置使用了Cyrus SASL认证解决。这一缺陷被引入与Postfix的SASL补丁,是存在于所有的后缀版本里命令“postconf mail_release_date”报道了20000314的值(2000年3月14日)或更高。请注意,CVE - 2011 - 1720不影响使用postfix的SMTP服务器达夫科特SASL认证。它也不会影响共同postfix的SMTP服务器的配置,只使用了Cyrus SASL机制平原和登录。
标签: Bugfixes, Stable, Security
This version contains a fix for CVE-2011-1720, which affects Postfix SMTP server configurations that use Cyrus SASL authentication. This defect was introduced with the Postfix SASL patch, and is present in all Postfix versions where the command "postconf mail_release_date" reports a value of 20000314 (March 14, 2000) or greater. Note that CVE-2011-1720 does not affect Postfix SMTP servers that use Dovecot SASL authentication. It also does not affect the common Postfix SMTP server configurations that use only Cyrus SASL mechanisms PLAIN and LOGIN.

2011-03-30 23:51

当客户端断开连接,然后重新连接之前,在较早的会话的所有DNSBL结果到了,在此之前的会议DNSBL结果将被添加到得分为后来的会议。在SMTP客户端不支持邮件到[IPv6的:ipv6addr]。 FreeBSD的closefrom()回来了,移植到FreeBSD 7,打破追溯的FreeBSD 7.x的支持。 SUN的编译器有一个指针表达式的形式“(”文本1“,”文本2“)+ ''麻烦不断。
标签: Bugfixes, 2.8.x (Stable)
When a client disconnected and then reconnected before all DNSBL results for the earlier session arrived, DNSBL results for the earlier session would be added to the score for the later session. The SMTP client did not support mail to [ipv6:ipv6addr]. FreeBSD closefrom() was back-ported to FreeBSD 7, breaking FreeBSD 7.x support retroactively. The SUN compiler had trouble with a pointer expression of the form "("text1" "text2") + constant''.

2011-03-10 11:12

此版本包含了一个针对CVE - 2011 - 0411修复程序,它允许超过TLS的纯文本的SMTP会话命令注入。这一缺陷是引入Postfix的版本2.2。同样的漏洞存在于STARTTLS命令的其他实现。
标签: 2.7.x, Security
This release contains a fix for CVE-2011-0411, which allows plain text command injection with SMTP sessions over TLS. This defect was introduced with Postfix version 2.2. The same flaw exists in other implementations of the STARTTLS command.

2011-02-24 00:43

标签: Bugfixes, 2.8.x (Stable)
This release fixes one "signal 11" bug with SMTP server debug logging, and cleans up some code and documentation.

2011-01-29 07:02

该postscreen守护现在包括稳定的版本。 postscreen现在支持TLS和可以登录被拒绝发件人,收件人和HELO中的信息。 DNS的白名单和过滤模式匹配从DNS白名单/黑名单服务器的响应支持加入。改进的邮件跟踪在基于SMTP的内容过滤器,经过过滤SMTP服务器可以登录前过滤器队列的ID。只读SQLite数据库支持加入。为'尾'是追加到SMTP服务器“拒绝”响应支持加入。
The postscreen daemon is now included with the stable release. postscreen now supports TLS and can log the rejected sender, recipient, and helo information. Support for DNS whitelisting and for pattern matching to filter the responses from DNS whitelist/blacklist servers was added. Improved message tracking across SMTP-based content filters; the after-filter SMTP server can log the before-filter queue ID. Read-only support for SQLite databases was added. Support for 'footers' that are appended to SMTP server "reject" responses was added.

