2.2.10 Ensure IMAP and POP3 server are not installed

Information

dovecot-imapd and dovecot-pop3d are an open source IMAP and POP3 server for Linux based systems.

Unless POP3 and/or IMAP servers are to be provided by this system, it is recommended that the package be removed to reduce the potential attack surface.

Solution

Run one of the following commands to remove dovecot-imapd and dovecot-pop3d :

# apt purge dovecot-imapd dovecot-pop3d

See Also

https://workbench.cisecurity.org/benchmarks/13007

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: fabe38945acb9cdf4e161cba101657eb7cde133e478586a4ac93e39a82d4a3b5