There are 2 open security issues in buster.
2 issues left for the package maintainer to handle:
- CVE-2020-35679:
(needs triaging)
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.
- CVE-2020-35680:
(needs triaging)
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine does not properly maintain the I/O channel between the SMTP engine and the filters layer.
You can find information about how to handle these issues in the security team's documentation.