Security Problem - syslog (sendmail)

From: Aharon <aharon_at_osfstats.health.gov.il>
Date: 24 Oct 1995 11:06:02 +0200

--
Hi all.
	CERT Advisory CA-95:13
(ftp://info.cert.org/pub/cert_advisories/CA-95:13.README) warns about
a security problem associated with syslog. The solution is to get a
patch from your vendor (Digital). In the meantime, there is a partial
workaround - for sendmail. It involves installing sendmail version
8.7.1. My questions:
	1. Has anyone heard about a syslog patch from Digital ?
	2. Has anyone installed sendmail 8.7.1 ? It is available from
		ftp://ftp.cert.dfn.de/pub/tools/net/sendmail/. Has
		anyone installed a previous sendmail version from cert ?
		If so, is there anything special to know ? Does it
		have any non-transparent effects ? Do you have to
		change some definition files or anything ?
Thanks in advance.
-- 
--
	Smile - Tomorrow Will be worse		Aharon Schkolnik
						Aharon_at_Matat.Health.Gov.IL
			-- Murphy
Received on Tue Oct 24 1995 - 15:13:08 NZDT

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:46 NZDT