[Dovecot] STARTTLS MITM in Postfix

Timo Sirainen tss at iki.fi
Mon Mar 7 22:35:29 EET 2011


http://marc.info/?l=postfix-users&m=129952854117623&w=2

Dovecot doesn't have this bug. It discards all buffered data when STARTTLS command runs.

(Why do I think I've heard about this bug before? Or at least the same type of way to exploit it? Maybe there was another similarly exploitable bug.)



More information about the dovecot mailing list