eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers to conduct DNS spoofing.
| Software | From | Fixed in |
|---|---|---|
| extremail / extremail | 2.1 | 2.1.x |
| extremail / extremail | 2.1.1 | 2.1.1.x |