Postfix contains a design flaw which may allow an attacker to use the mail server in SMTP 'bounce' scanning or even DDoS attacks. A specially crafted recipient field can cause the mail server to connect and communicate with an arbitrary host/port.
Upgrade to version 1.1.12 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround: set append_dot_mydomain to "yes" and resolve_dequoted_address to "no".