On 24/04/12 09:08 PM, Jonathan Adams wrote:
Dovecot's take on Qmail (and other MTA's http://wiki.dovecot.org/MTA )
which states "qmail is an obsolete and unmaintained server. Its POP3
part can be taken over by Dovecot. Qmail started off boasting about
speed and security in the mid-1990s, but has lots of unfixed bugs
(this document includes patches where known), among them security bugs
that remain unfixed, and the security guarantee (500 USD) denied. If
you really intend to continue using it, read Dave Sill's Life with
qmail which contains instructions to work around some of qmail's
security issues. "


DJB coughed up the goods for the dnscache security hole. The qmail-smtpd one is rather contrived (read: only 'demonstrated' in a very particular setup with a particular compiler on a particular operating system) and most probably never going to see the light of day.

The only fair comment there is 'obsolete and unmaintained'.

_______________________________________________
OpenIndiana-discuss mailing list
[email protected]
http://openindiana.org/mailman/listinfo/openindiana-discuss

Reply via email to