[8404] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Sendmail, lynx, Netscape, sshd, Linux kernel (twice)

daemon@ATHENA.MIT.EDU (Alan Cox)
Wed Nov 4 16:49:33 1998

Date: 	Tue, 3 Nov 1998 19:18:27 +0000
Reply-To: Alan Cox <alan@LXORGUK.UKUU.ORG.UK>
From: Alan Cox <alan@LXORGUK.UKUU.ORG.UK>
X-To:         wietse@PORCUPINE.ORG
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To:  <19981101022409.C7A63458B7@spike.porcupine.org> from "Wietse
              Venema" at Oct 31, 98 09:24:09 pm

> This attack is specific to LINUX. On UNIX systems with a BSD TCP/IP
> protocol stack, the accept() call does not return until the three-way
> handshake completes.
>
> Please do not blame Sendmail for every problem in the world.

The fact the sendmail people have been aware of this for over 2 years
and refused to consider putting a Linux case in for existing Linux
installations speaks volumes however. And yes Linux 2.1.x matches
BSD behaviour here.

Alan, still waiting for POSIX to finish standardising the socket API.

home help back first fref pref prev next nref lref last post