Re: STARTTLS bug -- [Zimbra]

2011-03-08 Thread Victor Duchovni
On Tue, Mar 08, 2011 at 06:26:47PM -0800, Quanah Gibson-Mount wrote: > > > --On March 8, 2011 10:20:21 AM -0800 Walter Smith > wrote: > >> >> Hi there! >> >> How severe this bug is? > > The CVE gave it 1.39 out of a possible 180 points. Or < 2%. > > It will of course be addressed in a later Zim

Re: STARTTLS bug -- [Zimbra]

2011-03-08 Thread Quanah Gibson-Mount
--On March 8, 2011 10:20:21 AM -0800 Walter Smith wrote: Hi there! How severe this bug is? The CVE gave it 1.39 out of a possible 180 points. Or < 2%. It will of course be addressed in a later Zimbra release. --Quanah -- Quanah Gibson-Mount Principal Software Engineer Zimbra, Inc --

Re: STARTTLS bug -- [Zimbra]

2011-03-08 Thread Wietse Venema
Walter Smith: > Hi there! > ? > How severe this bug is? Please read the announcement, section "overview and impact". http://www.postfix.org/CVE-2011-0411.html "This is not as big a problem as it may appear to be. The reason is that many SMTP client applications don't verify server TLS certificate

Re: STARTTLS bug -- [Zimbra]

2011-03-08 Thread Walter Smith
Hi there!   How severe this bug is?   I'm running few Zimbra servers and seems like it's there:     % telnet 0 25 220 myzimbra ESMTP Postfix starttls 220 2.0.0 Ready to start TLS   % telnet 0 587 220 myzimbra ESMTP Postfix starttls 220 2.0.0 Ready to start TLS     Should I disable it for now - is t