Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 164623 - mail-mta/netqmail-1.05-r4 doesn't include all qmail-1.03-r16 open relay protections
Summary: mail-mta/netqmail-1.05-r4 doesn't include all qmail-1.03-r16 open relay prote...
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Qmail Team (OBSOLETE)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-01-30 23:01 UTC by deurk
Modified: 2007-01-31 08:27 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments
Result of a qmail-1.03-r16 open relay test (qmail.txt,4.35 KB, text/plain)
2007-01-30 23:02 UTC, deurk
Details
Result of a netqmail-1.05-r4 open relay test (netqmail.txt,4.41 KB, text/plain)
2007-01-30 23:04 UTC, deurk
Details

Note You need to log in before you can comment on or make changes to this bug.
Description deurk 2007-01-30 23:01:04 UTC
Spotted differences to an open relay testing between qmail-1.03-r16 and netqmail-1.05-r4 by just changing the binaries compiled in /var/qmail/bin.

Since netqmail is now the default for virtual/qmail, you may want to provide the same level of security that before mid-january. Might be a missing patch.

Thanks.

Reproducible: Always

Steps to Reproduce:
1. Configure a mail server with netqmail-1.05-r4
2. Run http://www.rbl.jp/cgi-bin/svcheck.cgi?hostname=MAIL.DOMAIN.TLD&lang=en
3. Replace /var/qmail/bin binaries by the same compiled with qmail-1.03-r16
4. Run the same URL again

Actual Results:  
Differences in results

Expected Results:  
Identical results
Comment 1 deurk 2007-01-30 23:02:56 UTC
Created attachment 108693 [details]
Result of a qmail-1.03-r16 open relay test

No relaying at all at the end of the test
Comment 2 deurk 2007-01-30 23:04:40 UTC
Created attachment 108695 [details]
Result of a netqmail-1.05-r4 open relay test

7 tests relayed
Comment 3 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2007-01-31 08:27:20 UTC
Most likely this is because we don't patch netqmail like we did with qmail. Please bug upstream (http://www.qmail.org/netqmail/) or use a custom patch if this is an issue for you. We won't add any non-upstream suggested patches to the mail-mta/netqmail ebuild because anything else would end in the same mess as mail-mta/qmail.