Re: Sendmail

From: Hajimu UMEMOTO (ume@mahoroba.org)
Date: 08/30/01


Date: Fri, 31 Aug 2001 05:04:49 +0900 (JST)
To: mike@sentex.net
From: Hajimu UMEMOTO <ume@mahoroba.org>


>>>>> On Thu, 30 Aug 2001 15:43:17 -0400
>>>>> Mike Tancsa <mike@sentex.net> said:

mike> Probably not.. But, you never know. Someone could devise some clever way
mike> for some other process to exploit the bug.

sendmail 8.11.15 had local-exploit. If you use old version of
sendmail, you must upgrade to 8.11.16. Don't forget to drop setuid
bit of old sendmail binary or remove it.

mike> At 04:42 PM 8/30/01 -0300, Ronan Lucio wrote:
>Hi all,
>
>If I have a machine that any user has shell access. Itīs just a mail server.
>Is such machine vulnerable for sendmail?

--
Hajimu UMEMOTO @ Internet Mutual Aid Society Yokohama, Japan
ume@mahoroba.org  ume@bisd.hitachi.co.jp  ume@{,jp.}FreeBSD.org
http://www.imasy.org/~ume/
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: 2 questions about mail server
    ... >> tony did not get the mail from mike. ... > As delivered by Red Hat, sendmail will not accept incoming mail ... I edit sendmail.mc for other purposes, ...
    (linux.redhat)
  • Re: Sendmail on FreeBSD (OT)
    ... Mike wrote: ... > Have spamassassin, qpopper, sendmail all working to gether nicely. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Email problems caused by running out of disk space
    ... "Mike" wrote in message ... outside our network and also to send and recieve mail for local users. ... However still no incoming mail from outside the network. ... I've restarted sendmail but that doesn't seem to make any difference. ...
    (comp.unix.solaris)
  • Re: 2 questions about mail server
    ... On Thu, 12 Feb 2004, mike wrote: ... > users can send and get emails by using sendmail server within local network ... > user mike can send an email to tony by using either ...
    (linux.redhat.misc)
  • Re: simple send mail
    ... Mike - EMAIL IGNORED wrote: ... > the mail capability so that it knows about my provider, ... The available literature on sendmail is daunting, ... Smarthost. ...
    (linux.redhat.install)