Topic: vunreabilities in iredmail new install
I have installed iredmail 0.9.1 and found some security vulnerability:
* OpenSSL Running Version Prior to 1.0.1i
1- Apache Running Version Prior to 2.4.12
2- OpenSSL Running Version Prior to 1.0.1j (POODLE)
3- Apache Running Version Prior to 2.4.8
4- Apache NULL Pointer Dereference DoS
5- Apache Running Version Prior to 2.4.10
6- OpenSSL Running Version Prior to 1.0.1h
*Low
1- OpenSSL Version Detection
2- IMAP Service STARTTLS Command Support
3- SMTP Service STARTTLS Command Support
4- TCP Timestamps Retrieval
5- HTTP Packet Inspection
6- HTTP TRACE Method XSS Vulnerability
7- Directory Scanner
8- ICMP Timestamp Request
How do I update Apache and openSSL, etc?
==== Required information ====
- iRedMail version: 0.9.1
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): mysql
- Web server (Apache or Nginx): apache
- Linux/BSD distribution name and version: lunix
- Related log if you're reporting an issue: security
====
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.