Earlier quoted context omitted.
> CVE-2011-1720 and CVE-2008-2936 are examples of postfix vulns no one has found, or reasonably expects to find, in djb code. CVE-2011-1720 is related to SMTP authentication which qmail doesn't support out-of-the box. So. Yes you're right: You don't find that vulnerability in qmail because qmail doesn't have that feature. Can you run an SMTP server without authentication these days? Not if you have users using you as…
Road warriors with Thunderbird may need SMTP authentication, but most people do relaying with just IP authentication just fine.
Because if you disable a feature you don't use, you won't be affected by the vulnerability.
If you use smtp authentication, you're not running djb's code and all advantages of djb's code are moot. If you don't use smtp authentication then that CVE is inconsequential and you can't count it as a black mark against Postfix with regards to the security of your specific setup.