never stop questioning

8lgm-16u.txt

8lgm-16u.txt
Posted Sep 23, 1999

8lgm-16u.txt

MD5 | 891de4050677ea932bcf3539e7d80185

8lgm-16u.txt

Change Mirror Download

This advisory has been sent to:

comp.security.unix
Sun Microsystems <security-alert@sun.com>

===============================================================================
[8lgm]-Advisory-16.UNIX.sendmail-6-Dec-1994.UPDATE


PROGRAM:

sendmail(8)

UPDATE:

After further investigation, it has been discovered that SVR4 based
ports include sendmail(8) based on SMI code. This code therefore
is affected by the problem discussed in:

[8lgm]-Advisory-16.UNIX.sendmail-6-Dec-1994

Any systems running SMI sendmail(8) should follow advice given in
this advisory, and remove any set bits on sendmail(8).

To give more time to administrators to fix this problem, and due
to other problems being published this week, the exploit script
will now be posted at 00:00GMT on Monday 6th February 1995.

To retrieve these details, send a mail containing the line:

send [8lgm]-Advisory-16.UNIX.sendmail-6-Dec-1994-EXPLOIT

to 8lgm-fileserver@bagpuss.demon.co.uk. Requests for the script
to be sent before this date will be directed to /dev/null.

FIX:

We recommend that security conscious sites upgrade immediately
to UCB Sendmail 8.6.9, as Suns sendmail is generally recognised
as being broken. Your options are:

1. Obtain patch from your vendor.

2. Build and install sendmail 8.6.9, available from:
ftp.cs.berkeley.edu:/ucb/sendmail/sendmail.8.6.9.*

3. Remove set bits from any SMI sendmail(8) binaries.

FEEDBACK AND CONTACT INFORMATION:

8lgm-request@bagpuss.demon.co.uk (Mailing list additions -
processed automatically;
just send any message)

8lgm@bagpuss.demon.co.uk (Everything else)


NB: 8lgm-bugs@bagpuss.demon.co.uk has been closed.

8LGM MAILING LIST:

Send any message to 8lgm-request@bagpuss.demon.co.uk and the
address you mail from will automatically be added to the list.

If you need to subscribe to an address you cannot mail from
(eg an alias), send mail to 8lgm@bagpuss.demon.co.uk and request
to be added to the list. Due to our mail volume, we appreciate
it if you can use 8lgm-request instead; thus if you need to
subscribe an alias, please look into using, say sendmail -f,
if possible.

8LGM FILESERVER:

All [8LGM] advisories may be obtained via the [8LGM] fileserver.
For details, 'echo help | mail 8lgm-fileserver@bagpuss.demon.co.uk'
===========================================================================


Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close