Where
-Infinity
0
Severity
6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

First published (updated )
Severity
6.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Incorrect query parsing

Impact All users of versions prior to 0.5.1 can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.

Patches Problem has been patched in version 0.5.1

Workarounds Users may remediate this vulnerability without upgrading by applying these patches to older suppoorted versions.

For more information If you have any questions or comments about this advisory: Open an issue in postfix-mta-sts-resolver repo Email me at vladislav at vm-0 dot com

1 / 2
Source: GitHub
First published (updated )
Severity
6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C

DISPUTED postfixgroups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfixgroups.stdout, (2) /tmp/postfixgroups.stderr, and (3) /tmp/postfixgroups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it."

1 / 2
First published (updated )
Severity
6.8
Command Injection
AV:N/AC:M/Au:N/C:P/I:P/A:P

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

First published (updated )
Severity
6.8
Buffer Overflow
AV:N/AC:M/Au:N/C:P/I:P/A:P

A heap-based buffer overread flaw was found in the way Postfix mail transport agent performed SASL handlers management for SMTP sessions, when the Cyrus SASL authentication was enabled. A remote attacker could use this flaw to cause Postfix smtpd server crash via specially-crafted SASL authentication request.

Note: The default configuration of Postfix mail transport agent, as shipped with Red Hat Enterprise Linux 4, 5, and 6 do not enable SASL support for SMTP authentication for mail clients (thus Postfix server instances using it are not vulnerable to this flaw).

Workaround: If your Postfix server configuration contains directive like:

smtpdsaslauthenable = yes

change 'yes' to 'no' or comment the whole line out not to be vulnerable to this flaw.

1 / 2
Source: Red Hat
First published (updated )
Severity
6.5
SQL Injection
AV:N/AC:L/Au:S/C:P/I:P/A:P

Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysqlencrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php.

First published (updated )
Severity
6.2
AV:L/AC:H/Au:N/C:C/I:C/A:C

Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.

1 / 2
First published (updated )
Severity
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

DISPUTED A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \xce\xbf to the 'o' character. This is potentially relevant when the /etc/postfix/senderlogin feature is used, because a spoofed outbound message that uses a configured sender address is blocked with a "Sender address rejected: not logged in" error message, but a spoofed outbound message that uses a homoglyph of a configured sender address is not blocked. NOTE: some third parties argue that any missed blocking of spoofed outbound messages - except for exact matches to a sender address in the /etc/postfix/senderlogin file - is outside the design goals of Postfix and thus cannot be considered a Postfix vulnerability.

1 / 2
First published (updated )
Severity
4

A heap-based buffer overread flaw was found in the way Postfix mail transport agent performed SASL handlers management for SMTP sessions, when the Cyrus SASL authentication was enabled. A remote attacker could use this flaw to cause Postfix smtpd server crash via specially-crafted SASL authentication request.

Note: The default configuration of Postfix mail transport agent, as shipped with Red Hat Enterprise Linux 4, 5, and 6 do not enable SASL support for SMTP authentication for mail clients (thus Postfix server instances using it are not vulnerable to this flaw).

Workaround: If your Postfix server configuration contains directive like:

smtpdsaslauthenable = yes

change 'yes' to 'no' or comment the whole line out not to be vulnerable to this flaw.

First published (updated )
Severity
1.9
Infoleak
AV:L/AC:M/Au:N/C:P/I:N/A:N

Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.

First published (updated )

----- Forwarded message from Wietse Venema via Postfix-announce <postfix-announce () postfix org> -----

To: Postfix announce <postfix-announce () postfix org> Date: Tue, 8 Sep 2026 07:56:36 -0400 (EDT) CC: Postfix users <postfix-users () postfix org> Subject: [pfx-ann] Postfix stable release 3.11.7 and legacy releases 3.10.14, 3.9.15, From: Wietse Venema via Postfix-announce <postfix-announce () postfix org> Reply-To: Wietse Venema <wietse () porcupine org>

[An on-line version of this announcement will be available at https://www.postfix.org/announcements/postfix-3.11.7.html]

This release addresses medium-impact problems that need to be fixed as some enable remote DOS or SMTP smugggling.

The fixes below, and more, are also released in the unstable version postfix-3.12-20260902.

In addition to updated releases for the supported Postfix versions 3.8-3.11, releases will also be available for the out-of-support Postfix versions 3.5-3.7. NOTE: these do not include the patches for out-of-support Postfix versions that have been issued for "large SMTP inputs (June 2026)", and for "TLSA parsing (June 2026)". Those patches still need to be applied.

These defects were found by "Qualys assisted by Claude Mythos Preview", and by "OpenAI Security"; three date from 20 or more years ago.

SMTP smuggling:

Bug (introduced: Postfix 3.9, date: 20240106) SMTP smuggling was still possible with smtpdproxyfilter (disabled by default) when the after-filter SMTP server used the default policy settings "smtpdforbidbarenewlineexclusions = $mynetworks" and "smtpdforbidbarenewline = normalize". Reported by OpenAI Security. Fix by Wietse.

As suggested by OpenAI Security, eliminate stray CR characters from the smtpdproxyfilter input stream. The before-proxy-filter SMTP server already eliminated stray LF.

Bug (introduced: Postfix 3.11, date: 20250917): SMTP smuggling was possible with smtpdproxyfilter (disabled by default) when the before-filter SMTP server added a "Require-TLS-ESMTP: yes" message header, due to implementation edge cases. Adding this header is enabled with the "requiretlsesmtpheader = yes" default setting. Reported by OpenAI Security. Fix by Wietse.

Server crashes and panic()s:

Bug (defect introduced: Postfix 3.0, date: 20140707): null pointer read error after receiving MAIL FROM, RCPT TO, and VRFY with an UTF8 address but no SMTPUTF8 parameter. This requires "smtputf8enable = yes" (the default) and "strictsmtputf8 = yes" (not default). With this, the SMTP server did an unnecessary MAIL FROM reset without RCPT TO reset. A crafted remote SMTP client could then send a DATA command and crash a Postfix SMTP server process with a null pointer read error. Reported by Wonyoung Jung (78ResearchLab AI).

Other bugs

Bug (defect introduced: Postfix 3.4, date: 20180303): the MySQL client setting "tlsverifycert = yes" had no effect with Oracle MySQL 8 and later. Report and fix by OpenAI Security.

Bug (defect introduced: Postfix-beta, date: 19990119): the pipe(8) delivery agent deleted a command-line argument if the argument contained $user AND $user expanded to an empty string, breaking the positional order of arguments. This was a workaround for a problem that hopefully no longer exists. Reported by Qualys, assisted by Claude Mythos Preview.

Bug (defect introduced: Postfix 2.3, date: 20050323): the SMTP client enhanced status code parser could process stale data when a remote SMTP server sent a three-digit reply without other text. Reported by Qualys, assisted by Claude Mythos Preview.

TLS

Isolation: stamp Postfix SMTP server TLS session tickets with their master.cf service name. With this, an SMTP server defined in master.cf will no longer accept tickets issued by a different SMTP server defined in the same master.cf file. Fix by OpenAI security.

Configuration safety

The postmap and postalias commands now log a warning when creating a root-owned database file in a directory that is not owned by root. They log that the database source file, indexed file(s), and parent directory should have the same owner, to prevent a privilege-escalation attack. Problem reported by OpenAI Security, remediation strategy (don't break production deployment) by Wietse.

Read after free, memory over-read

Bug (introduced: Postfix 2.3, date: 20060629): a malicious Milter or attacker-in-the-middle could trigger a null-terminated heap memory overread in the SMTP daemon while formatting a malformed multiline response. Fix from OpenAI Security adopted with minor changes.

Bug (defect introduced: Postfix 3.0, date: 20141117): in the postqueue command don't free() text before logging a fatal error message. Reported by Qualys, assisted by Claude Mythos Preview.

Code hygiene: in the SMTP client protocol engine, evaluate a RETURN() macro argument before freeing resources. Reported by Qualys, assisted by Claude Mythos Preview.

Code hardening (defense in depth, prevention)

(Postfix 3.11) Hardening: in the non-BerkeleyDB migration service, delay the decision between running postmap or postalias until after the database file/directory owner/permission checks. The benefit from making the decision early (better error messages) was not worth the risk. Qualys, assisted by Claude Mythos Preview.

(Postfix-3.11) Hardened the database parent directory permission checks for automatic re-indexing with the non-Berkeley-DB migration service.

Hardening command-line email submission: the postdrop command now disallows null and line-break characters in queue file envelope records (line-break characters in non-envelope queue file records are already neutralized by default with "cleanupreplacestraycrlf = yes").

The new constraint not only eliminates line-break injection into local mailbox files as reported by OpenAI Security, but also prevents other forms of misuse. Later, this constraint may be moved into the Postfix core. Fix by Wietse.

Shut up nagging from multiple AIs and harden the virtual delivery agent against an evil (LDAP or SQL) database.

Code hygiene: myrealloc(ptr, 0) still resulted in a panic. Reported by Qualys, assisted by Claude Mythos Preview. Also adopt a mystrndup() fix from Postfix 3.12.

Other:

Portability: OpenBSD does not define NSINT16SZ. Brad Smith.

You can find the updated Postfix source code on the mirrors listed at https://www.postfix.org/.

Wietse Postfix-announce mailing list -- postfix-announce () postfix org To unsubscribe send an email to postfix-announce-leave () postfix org

----- End forwarded message -----

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203