Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 104879

Summary: vchkpw always returns true in smtp-auth, resulting in an open relay mail server.
Product: Gentoo Security Reporter: Maurits Lamers <maurits>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED INVALID    
Severity: major    
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Maurits Lamers 2005-09-05 04:27:25 UTC
SMTP-Authentication always succeeds, even when the password given is not correct and as long as the 
password is not empty. It does not matter if the user name used for authentication is a valid user for 
the virtual domains.



Reproducible: Always
Steps to Reproduce:
1. Set up a qmail/vpopmail server using the gentoo qmail/vpopmail guide (http://www.gentoo.org/
doc/en/qmail-howto.xml). 
2. Try to send a message using fake authentication.
3. 

Actual Results:  
Mail sends normally

Expected Results:  
Mail should be refused due to false authentication...

Running on Gentoo 2005.0, qmail-1.03-r13, vpopmail-5.4.6-r1, server set up using the qmail/
vpopmail guide.

I checked all configuration at least 5 times already, unable to find anything wrong.
Comment 1 Maurits Lamers 2005-09-05 05:12:41 UTC
Sorry, the error was a result of a typing error in the configuration file conf-smtp...

Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-09-05 05:28:12 UTC
Reopening for proper closure. 
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-09-05 05:28:51 UTC
Closing as invalid.