Re: [Exim] Relaying in Exim 3.12

Top Page
Delete this message
Reply to this message
Author: Florian Weimer
Date:  
To: exim-users
CC: steve
Subject: Re: [Exim] Relaying in Exim 3.12
Steve Meier <steve@???> writes:

> Exim 3.12 obviously allows relaying in the following setup:
>
> Hostname e.g.: mail.customer.com
> Envelope-Sender: <postmaster@???>
>
> Is this problem fixed in any newer version of Exim ? Can I
> recommend our customers to update ?


If the Exim configuration is unsual or explicitly allowing relaying,
even more recent Exim versions can become open relays.

However, your customers should update anyway and then check the
configuration since Exim 3.12 has several security holes, AFAIK.

--
Florian Weimer                       Weimer@???
University of Stuttgart           http://CERT.Uni-Stuttgart.DE/people/fw/
RUS-CERT                          +49-711-685-5973/fax +49-711-685-5898