← Back to team overview

nagios-charmers team mailing list archive

[Bug 1843863] Re: Postfix installed listens on all interfaces by default

 

** Information type changed from Public to Private Security

** Changed in: nagios-charm
       Status: New => Confirmed

** Changed in: nagios-charm
   Importance: Undecided => High

-- 
You received this bug notification because you are a member of Nagios
Charm developers, which is subscribed to Nagios Charm.
https://bugs.launchpad.net/bugs/1843863

Title:
  Postfix installed listens on all interfaces by default

Status in Nagios Charm:
  Confirmed

Bug description:
  When installing a fresh Nagios unit, Postfix is pulled in as a
  dependency.  A security audit has pulled up that although the config
  doesn't allow open relay, there is an SSL vulnerability of note that
  needs fixing (https://discussions.qualys.com/docs/DOC-1097).  Although
  that's an issue for a different package, we have no need for Postfix
  to even listen on all interfaces and it should be reconfigured to only
  listen on localhost.

To manage notifications about this bug go to:
https://bugs.launchpad.net/nagios-charm/+bug/1843863/+subscriptions


References