Re: FreeBSD Security Advisory FreeBSD-SA-01:60.procmail

From: Nate Williams (nate@yogotech.com)
Date: 09/24/01


From: Nate Williams <nate@yogotech.com>
Date: Mon, 24 Sep 2001 15:09:39 -0600
To: Kris Kennaway <kris@obsecurity.org>


> > > =============================================================================
> > > FreeBSD-SA-01:60 Security Advisory
> > > FreeBSD, Inc.
> > >
> > > Topic: Multiple vulnerabilities in procmail signal handling
> > > V. Solution
> > >
> > > The port procmail-3.20 and later versions include fixes for these
> > > vulnerabilities.
> >
> > I'm guessing this is supposed to be procmail-3.21 and later?
>
> No, it's meant to be 3.20 and later.

Ahh, I read the vulnerability wrong. It says

     procmail versions prior to procmail 3.20 performed unsafe actions
     while in the signal handlers.

I didn't parse 'prior to procmail 3.20' very well.

I'm sorry, my bad, ....

Nate

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: FreeBSD Security Advisory FreeBSD-SA-01:
    ... > So then I'm guessing this has been 3.5-STABLE is not vulnerable? ... but RELENG_3 is no longer supported for local security ... vulnerabilities as announced a few months ago; ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • OpenSSL security issues
    ... For those not on bugtraq looks like ... there are a series of vulnerabilities for openssl. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: FreeBSD Security Advisory FreeBSD-SA-01:
    ... but it looks like this bug was enabled by ... > security fixes for locally exploitable vulnerabilities under RELENG_3, ... > only network-exploitable vulnerabilities. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: File table exhaustion patch
    ... Is that the official FreeBSD SO team viewpoint on local DoS ... Ciao, ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)