|
|||||||||||
|
remote buffer overflow in sendmail
From: Todd C. Miller <Todd.Miller(at)courtesan.com>
Date: Mon Mar 03 2003 - 12:49:33 EST
For more information, see: http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21950 http://www.sendmail.org/8.12.8.html As shipped, OpenBSD runs a sendmail that binds only to localhost, making this a localhost-only hole in the default configuration. However, any sendmail configuration that accepts incoming mail may potentially be exploited. The sendmail in OpenBSD-current has been updated to version 8.12.8. The 3.1 and 3.2 -stable branches have had a patch applied that fixes the buffer overflow. However, because the -stable branches have the specific vulnerability patched (as opposed to the full 8.12.8 distribution), sendmail on -stable will report the old sendmail version.
Patch for OpenBSD 3.1:
Patch for OpenBSD 3.2:
Patches for older versions of sendmail may be found at ftp://ftp.sendmail.org/pub/sendmail/ Received on Mon Mar 3 12:51:52 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:46:07 EDT |
||||||||||
|
|||||||||||