oss-sec mailing list archives

Re: Authentication vulnerabilities in OpenBSD


From: Arrigo Triulzi <arrigo () alchemistowl org>
Date: Thu, 5 Dec 2019 12:04:45 +0100

On 5 Dec 2019, at 11:44, Georgi Guninski <gguninski () gmail com> wrote:

On Wed, Dec 4, 2019 at 10:51 PM Qualys Security Advisory <qsa () qualys com> wrote:


Qualys Security Advisory

Authentication vulnerabilities in OpenBSD


openbsd doesn't count these as remote holes in default install, right?

By default OpenSMTPd listens only on localhost:25 and is not configured to offer SMTP AUTH

Arrigo


Current thread: