LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-22-2006, 09:06 PM   #1
justanothersteve
Member
 
Registered: Aug 2005
Location: Missouri, USA
Distribution: Gentoo
Posts: 161

Rep: Reputation: 30
Security Flaw in Sendmail detected


Sorry if this has been posted already, I came across this article and thought I'd help spread the word to updgrade.

http://news.com.com/Sendmail+flaw+op...3-6052758.html

Again, I apologize if this has been posted
 
Old 03-22-2006, 09:34 PM   #2
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
I haven't seen it reported here (until now ) but the Sendmail mailing list notification of the availability of 8.13.6 is out and so is the Slackware Security mailing list's advisory for the new package.

Bugtraq also has notifications of updates for sendmail on FreeBSD and Suse (with others to follow I'm sure).

I only mention it as a plug for some sources of this kind of information...
 
Old 03-22-2006, 09:42 PM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
WARN: Critical Sendmail Vulnerability

ISS has identified a race condition in Sendmail that allows a remote attacker to execute arbitrary code with the privileges of the Sendmail user, often root. All Sendmail users are advised to immediately upgrade to version 8.13.6+. Thanks to justanothersteve for reporting this vuln.

Additional links:
http://www.securityfocus.com/bid/17192/discuss
http://www.sendmail.com/company/advi....shtml#exploit
 
Old 03-23-2006, 02:33 AM   #4
nx5000
Senior Member
 
Registered: Sep 2005
Location: Out
Posts: 3,307

Rep: Reputation: 57
Maybe time to switch to postfix?
 
Old 03-23-2006, 06:32 PM   #5
CrEsPo
Member
 
Registered: Apr 2005
Location: Canada
Distribution: Slackware 12
Posts: 184

Rep: Reputation: 30
Just found out about this, here's the CERT advisory.
 
Old 04-04-2006, 01:45 AM   #6
simcox1
Member
 
Registered: Mar 2005
Location: UK
Distribution: Slackware
Posts: 794
Blog Entries: 2

Rep: Reputation: 30
Are these security advisories really that critical? Apparently this Sendmail problem doesn't have anything to do with normal sending/receiving email. It's to do with some very specific connection conditions.
 
Old 04-04-2006, 09:08 AM   #7
nx5000
Senior Member
 
Registered: Sep 2005
Location: Out
Posts: 3,307

Rep: Reputation: 57
No its not critical it has just been rated 8/10 .. Could be 9 or 10

Btw sendmail.org is the original sendmail homepage. The .com have some patches to sendmail.org code.

"It's to do with some very specific connection conditions."
Very specific doesn't mean it can't be achieved, It's never good to minimize.
There is a remotely critical exploitable bug that doesn't need authentication.
There is a patch, you have to apply it. Easy
 
Old 04-04-2006, 11:44 PM   #8
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Quote:
Originally Posted by simcox1
Are these security advisories really that critical? Apparently this Sendmail problem doesn't have anything to do with normal sending/receiving email. It's to do with some very specific connection conditions.
There is already PoC code available for this. Given that you'd be executing arbitrary code as root, that's pretty bad in my book. Secunia lists this as "highly critical" though I've seen it as "high" too. I certainly wouldn't want to have a vulnerable version running when it goes from PoC to exploit in wild.
 
Old 04-09-2006, 10:36 AM   #9
king111
Member
 
Registered: Jul 2005
Distribution: Debian, Ubuntu
Posts: 85

Rep: Reputation: 15
Sendmail vulnerabilities ... Where have I heard that before? And, uh, yeah, any vulnerability that could potentially allow an attacker to root you is pretty bad. Race conditions aren't as critical as some might think, but they're still bad and especially bad with a highly popular MTA like sendmail.
 
Old 04-09-2006, 03:25 PM   #10
simcox1
Member
 
Registered: Mar 2005
Location: UK
Distribution: Slackware
Posts: 794
Blog Entries: 2

Rep: Reputation: 30
I know it's important to keep up to date etc, and apply patches, but I wonder how critical some of the updates are. Sometimes all you're doing is fixing a bug while installing a new one.
 
Old 05-09-2006, 04:16 PM   #11
gbell72
Member
 
Registered: Sep 2003
Location: Toronto, Canada
Distribution: FreeBSD
Posts: 78

Rep: Reputation: 15
I agree with nx5000, if you care about security whatsoever switch to postfix, or any other MTA for that matter that doesn't have near as many CERT advisories as Sendmail does.

Unless you are absolutely confident you understand sendmail configuration and macros, do not put sendmail on an internet accessible server.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
WARN PHP Vulnerability Capt_Caveman Linux - Security 0 07-04-2005 04:38 PM
WARN: Samba Vulnerability Capt_Caveman Linux - Security 0 12-17-2004 10:59 PM
WARN: OpenSSL NULL Pointer Assignment vulnerability unSpawn Linux - Security 1 03-18-2004 12:11 PM
Warn: mutt Joey.Dale Linux - Security 0 02-12-2004 08:46 PM
new sendmail vulnerability infamous41md Linux - Security 5 11-30-2003 06:38 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration