Welcome to our website
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
Sendmail Update for Cobalt RaQ
Posted by Philipp Esselbach on: 09/18/2003 04:47 PM [ Print | 0 comment(s) ]
Solarspeed has released sendmail packages for the Cobalt RaQ server appliances
Another vulnerability in Sendmail was announced today which could lead to a root exploit. These patches fix all three recent vulnerabilities which were found in Sendmail:
a.) A "Remote Header Processing Vulnerability" in Sendmail. Attackers may remotely exploit this vulnerability to gain "root" or superuser control of any vulnerable Sendmail server. The full details of this vulnerability are outlined in ISS X-Force's Advisory. This was fixed with Sun Cobalt Patch 16402 and 16429.
b.) Michal Zalewski found a vulnerability in Sendmail versions 8.12.8 and prior which could possibly lead to a remote root exploit. The findings are outline here. This was fixed with Sun Cobalt Patch 16429.
c.) NEW: Michal Zalewski found a vulnerability in Sendmail versions 8.12.9 and prior, which could possibly lead to a remote root exploit. The findings are outline here.
The PKGs above were built with the patches which the Sendmail consortium released to address this issue (patch a / patch b / patch c).
a.) A "Remote Header Processing Vulnerability" in Sendmail. Attackers may remotely exploit this vulnerability to gain "root" or superuser control of any vulnerable Sendmail server. The full details of this vulnerability are outlined in ISS X-Force's Advisory. This was fixed with Sun Cobalt Patch 16402 and 16429.
b.) Michal Zalewski found a vulnerability in Sendmail versions 8.12.8 and prior which could possibly lead to a remote root exploit. The findings are outline here. This was fixed with Sun Cobalt Patch 16429.
c.) NEW: Michal Zalewski found a vulnerability in Sendmail versions 8.12.9 and prior, which could possibly lead to a remote root exploit. The findings are outline here.
The PKGs above were built with the patches which the Sendmail consortium released to address this issue (patch a / patch b / patch c).
Read more
Related Threads
08/22/2005 09:50 PM: sendmail in suse 9.3 (0) by linusguy
