SpamAssassin Milter Plugin problems on PVE

Jun 12, 2020
26
7
23
Hi,

We currently have the problem that we have to upgrade the SpamAssassin Milter plugin from 0.3.X to 0.4 on all our Proxmox servers for security reasons.

Would there be a solution or workaround for this.
We have the problem with subscription systems and those without subscription.

PVE-INFO:
proxmox-ve: 7.2-1 (running kernel: 5.15.35-1-pve)
pve-manager: 7.2-4 (running version: 7.2-4/ca9d43cc)
pve-kernel-5.15: 7.2-4
pve-kernel-helper: 7.2-4
pve-kernel-5.13: 7.1-9
pve-kernel-5.15.35-2-pve: 5.15.35-5
pve-kernel-5.15.35-1-pve: 5.15.35-3
pve-kernel-5.15.30-2-pve: 5.15.30-3
pve-kernel-5.13.19-6-pve: 5.13.19-15
pve-kernel-5.13.19-5-pve: 5.13.19-13
pve-kernel-5.13.19-2-pve: 5.13.19-4
ceph: 16.2.7
ceph-fuse: 16.2.7
corosync: 3.1.5-pve2
criu: 3.15-1+pve-1
glusterfs-client: 9.2-1
ifupdown: 0.8.36+pve1
libjs-extjs: 7.0.0-1
libknet1: 1.24-pve1
libproxmox-acme-perl: 1.4.2
libproxmox-backup-qemu0: 1.3.1-1
libpve-access-control: 7.2-2
libpve-apiclient-perl: 3.2-1
libpve-common-perl: 7.2-2
libpve-guest-common-perl: 4.1-2
libpve-http-server-perl: 4.1-2
libpve-storage-perl: 7.2-4
libspice-server1: 0.14.3-2.1
lvm2: 2.03.11-2.1
lxc-pve: 4.0.12-1
lxcfs: 4.0.12-pve1
novnc-pve: 1.3.0-3
proxmox-backup-client: 2.2.3-1
proxmox-backup-file-restore: 2.2.3-1
proxmox-mini-journalreader: 1.3-1
proxmox-widget-toolkit: 3.5.1
pve-cluster: 7.2-1
pve-container: 4.2-1
pve-docs: 7.2-2
pve-edk2-firmware: 3.20210831-2
pve-firewall: 4.2-5
pve-firmware: 3.4-2
pve-ha-manager: 3.3-4
pve-i18n: 2.7-2
pve-qemu-kvm: 6.2.0-10
pve-xtermjs: 4.16.0-1
qemu-server: 7.2-3
smartmontools: 7.2-pve3
spiceterm: 3.2-2
swtpm: 0.7.1~bpo11+1
vncterm: 1.7-1
zfsutils-linux: 2.1.4-pve1

Many thanks
 
We currently have the problem that we have to upgrade the SpamAssassin Milter plugin from 0.3.X to 0.4 on all our Proxmox servers for security reasons.
spamassassin is not installed by default on Proxmox VE (which is a hypervisor distribution) - also I'm not sure why you would want to install SpamAssassin on a Proxmox VE node?

Proxmox Mailgateway on the other hand uses SpamAssassin (although not any of the available milter-packages that use SpamAssassin) - maybe you mean that?
 
Hi,

we just installed a new PVE Cluster incl. postfix (for testing) and started a vulnerability scan on it.

Same Problem:
SpamAssassin Milter Plugin 'ml_envrcpt()

Is there any way to remove it without deactivate postfix.

SpamAssassin is not installed, already checked.
 
we just installed a new PVE Cluster incl. postfix (for testing) and started a vulnerability scan on it.
How did you actually install it - with the PVE ISO, on top of debian?
What kind of additional packages did you install?
does spamassassin maybe get pulled in through some config-management tool of yours?

else - I'd say - just remove it:
* dpkg -l |grep -i spam # to see which packages might have been installed
* apt remove <packages that cause the issue>
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!