sendmail cert advisory

From: Yamnicky <uq626926_at_es.bss.boeing.com>
Date: Thu, 06 Mar 2003 11:09:35 -0800 (PST)

Managers,

I imagine most of you are aware of the most recent CERT advisory
CA-2003-07 Sendmail. Supposedly all versions prior to 8.12.8 are affected.

>From the README:
"This vulnerability is message-oriented as opposed to connection-
oriented. That means that the vulnerability is triggered by the contents
of a specially-crafted email message rather than by lower-level network
traffic."

HP/Compaq has a patch available for Tru64 5.1. The README file can be
found at
http://ftp.support.compaq.com/patches/public/Readmes/unix/t64v51b19-c0169100-168
82-es-20030211.README

I have a collection of alpha boxes running 4.0F with sendmail 8.8.8. Has
there been any discussion to date regarding a fix for those of us not
running 5.1?

Any information would be greatly appreciated.
Thank You
/Mark

--------------------------------------------------------------------

The most precious thing we have is life. Yet it has absolutely no trade-in
value.
Received on Thu Mar 06 2003 - 19:27:55 NZDT

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:44 NZDT