Posted By: peopleinside on January 21, 2016, 2:23 pm |
Hi,
if you go on Webuzo, App and search Dovecot you will see the last version is 2.09 but this is not correct is 2.1.1 used by webuzo. If you run SSH command: dovecot --version the version is 2.1.1 not the old 2.0.9 Also as discussed here: http://www.softaculous.com/board/index.php?tid=8490&title=Security_Issue_on_Dovecot_2.0.9 and here: http://www.softaculous.com/board/index.php?tid=8585&title=Security_Issue_EXIM_4.72 Webuzo is using as last Exim edition the version 4.72 relased on 2011 who have STRONG SECURITY ISSUE as seems to be vulnerable to the POODLE attack and can't have SSL 3 disabled or email won't work. Hope this two issue can be fixed ASAP, expecially Exim Security Issue. ----------------------- PeopleInside Web, security, open source passionate. |