[4954] in RedHat Linux List
Re: SECURITY: Important fix for sendmail
daemon@ATHENA.MIT.EDU (Jos Vos)
Mon Nov 18 10:32:39 1996
From: Jos Vos <jos@xos.nl>
To: redhat-list@redhat.com
Date: Mon, 18 Nov 1996 16:30:03 +0100 (MET)
In-Reply-To: <Pine.LNX.3.93.961118095557.7844R-100000@redhat.com> from "Erik Troan" at Nov 18, 96 10:03:07 am
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
Hi,
> All publically released versions of sendmail through 8.8.2 have a major
> security hole which allows any user of your system to gain root access. This
> is a architecture independent problem, which a single exploit working on
> all systems which use sendmail.
>
> Red Hat 4.0 users on all platforms are encouraged to upgrade to
> sendmail-8.7.6-5 as soon as possible. Red Hat 3.0.3 users should either upgrade
> to Red Hat 4.0 or look at Cristian Gafton's packages, available from
> ftp://sysadm.sorosis.ro/pub/fixes. Note that those fixes are *not* official
> fixes and have never been seen by anyone at Red Hat Software.
If this new revision (8.7.6-5) just includes an extra patch: can this
patch be posted separately to this list, so that everybody running
some 8.7.x sendmail with Red Hat 3.0.3 can regenerate the sendmail
package without the need to extract the patch from the 4.0 SRPM (which
is some work, given the new RPM format, etcetera)?
Thanks in advance.
--
-- Jos Vos <jos@xos.nl>
-- X/OS Experts in Open Systems BV | Phone: +31 20 6938364
-- Amsterdam, The Netherlands | Fax: +31 20 6948204
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null