Government of the Republic of Trinidad and Tobago
gov.tt

TTCSIRT-285.022620: TT-CSIRT ADVISORY- OPENSMTPD 6.6.4P1 RELEASE ADDRESSES CRITICAL VULNERABILITY

TTCSIRT-285.022620: TT-CSIRT ADVISORY- OPENSMTPD 6.6.4P1 RELEASE ADDRESSES CRITICAL VULNERABILITY

Qualys has found another critical vulnerability in OpenSMTPD.
It is very important that you upgrade your setups AS SOON AS POSSIBLE.

On OpenBSD: Binary patches are available through syspatch.
Just run the syspatch command and make sure that your OpenSMTPD was restarted:
$ doas syspatch

On other systems the released version 6.6.4p1 of OpenSMTPD addresses the vulnerability.

The Trinidad and Tobago Cyber Security Incident Response Team (TTCSIRT) encourages users and administrators to review and apply the necessary updates utilising the following links: 
https://www.opensmtpd.org/archives/opensmtpd-6.6.4p1.tar.gz
https://www.opensmtpd.org/archives/opensmtpd-6.6.4p1.sum.sig
 
It is also available from Github: 
https://github.com/OpenSMTPD/OpenSMTPD/releases/download/6.6.4p1/opensmtpd-6.6.4p1.tar.gz
https://github.com/OpenSMTPD/OpenSMTPD/releases/download/6.6.4p1/opensmtpd-6.6.4p1.sum.sig
 Or using the `6.6.4p1` tag if you're building from source.