RE: Can dovecot be leveraged to exploit Solr/Log4shell?

2021-12-13 Thread Aki Tuomi
Dovecot itself has no log4j vulnerability as Dovecot does not use Java or Log4j directly. Solr, however, does use log4j. Please see https://solr.apache.org/security.html#apache-solr-affected-by-apache-log4j-cve-2021-44228 for further information on upgrading or mitigating the issue. Aki > On 1

RE: Can dovecot be leveraged to exploit Solr/Log4shell?

2021-12-13 Thread Scott
Is this assuming you log at some verbose level ? What if you log at WARN or higher ? For production it seems kind of silly to log search queries anyways. Scott -Original Message- From: dovecot On Behalf Of John Fawcett Sent: Monday, December 13, 2021 8:52 PM To: dovecot@dovecot.org Su

Re: Can dovecot be leveraged to exploit Solr/Log4shell?

2021-12-13 Thread John Fawcett
On 13/12/2021 23:43, Joseph Tam wrote: I'm surprised I haven't seen this mentioned yet. An internet red alert went out Friday on a new zero-day exploit. It is an input validation problem where Java's Log4j module can be instructed via a specially crafted string to fetch and execute code from a

Can dovecot be leveraged to exploit Solr/Log4shell?

2021-12-13 Thread Joseph Tam
I'm surprised I haven't seen this mentioned yet. An internet red alert went out Friday on a new zero-day exploit. It is an input validation problem where Java's Log4j module can be instructed via a specially crafted string to fetch and execute code from a remote LDAP server. It has been desig

Dovecot, Solr (FTS) and iOS body search

2021-12-13 Thread Ben Howard
I had a question about full text search with Dovecot, Solr with iOS as a client (the built in default mail client). Does anyone happen to know if it's possible to get the iOS mail client to search bodies of email via IMAP with Dovecot and Solr on the server? I've looked at the IMAP queries bei

Re: dovecot-2.3.17: "Panic: file ioloop.c: line 865"

2021-12-13 Thread Claudio Corvino
Hi, I have the same error in my replica server, it appears many times per day. Log: /Dec 13 13:01:23 Error: doveadm(xxx)<25513>: read(xxx.xxx.xxx) failed: EOF (last sent=mailbox, last recv=mailbox)// //Dec 13 13:34:43 Warning: doveadm(xxx)<26277><9e2rJOM9t2GlZgAAbKtC3g>: /mnt/mail-storage-lv0

Re: Expunged message reappeared

2021-12-13 Thread Joelly Alexander
Hi Claudio, I've planned to upgrade them as well after Christmas - to hear you did it already and the issues are gone is great news. Thanks for sharing and looking forward to get it resolved for me as well soon... Thanks, Alex On 12/13/21 10:31 AM, Claudio Corvino wrote: Hi Alex, after

Re: Expunged message reappeared

2021-12-13 Thread Claudio Corvino
Hi Alex, after the upgrade to the latest stable version and after removing duplicated users that I had when launching "doveadm replicator status '*'" command (the results of the command gave me /user1/ and /us...@domain.com/ just to explain), it seems that reappearing messages, and most of al

Re: 2.3.17: Panic on LMTP deliveries

2021-12-13 Thread Volker Jungbluth
It WORKS!!! :-) Great, thanks! Best regards Volker Am 12.12.2021 um 13:00 schrieb Volker: That´s a good message, thank you very much! I will try the patch! Kind regards Volker Am 12.12.2021 um 12:48 schrieb Aki Tuomi: Hello! While searching for an explanation for the fact that after updat