Welcome to our website
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
Sendmail Update for Mandrake
Posted by Philipp Esselbach on: 09/18/2003 12:34 PM [ Print | 0 comment(s) ]
MandrakeSoft S.A. has released a security patch for Sendmail under Mandrake Linux
A buffer overflow vulnerability was discovered in the address parsing code in all versions of sendmail prior to 8.12.10 by Michal Zalewski, with a patch to fix the problem provided by Todd C. Miller. This vulnerability seems to be remotely exploitable on Linux systems running on the x86 platform; the sendmail team is unsure of other platforms (CAN-2003-0694).
Another potential buffer overflow was fixed in ruleset parsing which is not exploitable in the default sendmail configuration. A problem may occur if non-standard rulesets recipient (2), final (4), or mailer- specific envelope recipients rulesets are use. This problem was discovered by Timo Sirainen (CAN-2003-0681).
MandrakeSoft encourages all users who use sendmail to upgrade to the provided packages which are patched to fix both problems.
Another potential buffer overflow was fixed in ruleset parsing which is not exploitable in the default sendmail configuration. A problem may occur if non-standard rulesets recipient (2), final (4), or mailer- specific envelope recipients rulesets are use. This problem was discovered by Timo Sirainen (CAN-2003-0681).
MandrakeSoft encourages all users who use sendmail to upgrade to the provided packages which are patched to fix both problems.
Read more
Related Threads
08/22/2005 09:50 PM: sendmail in suse 9.3 (0) by linusguy
