Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Security Operating Systems BSD

FreeBSD Users: Time To Patch Sendmail Again 39

Barrett Lyon writes "The FreeBSD Project just submitted this security advisory out to the masses: "FreeBSD-SA-03:07.sendmail, a second sendmail header parsing buffer overflow." It seems that the overflow is not limited to FreeBSD and that there is currently no workaround "other than not using sendmail." Yet another good reason to run Qmail!"
This discussion has been archived. No new comments can be posted.

FreeBSD Users: Time To Patch Sendmail Again

Comments Filter:
  • Doesn't anyone on the /. team read before posting? This is the same hole that made the front page yesterday concerning the char to int conversion. Just cause one of the BSDs finally acknowleged the issue, it deserves *another* front page story? Jeez... upgrade to sendmail 8.12.9 and get on w/ your life...
  • by Phaid ( 938 ) on Sunday March 30, 2003 @09:27PM (#5628853) Homepage
    Just in case anyone's wondering, this is the same hole reported on Slashdot yesterday and reported in this CERT advisory [cert.org].

    I mention this because the FreeBSD posting doesn't explicitly mention which version of Sendmail this affects, but it does link to the CERT article.
  • What is interesting to me is that there has been quite a delay - over a day, so far as I can tell, between this sendmail update going into the CVS tree, first into -CURRENT, the following very quickly into -STABLE and the various RELANG 4_x out there, and it appearing as first a FreeBSD security advisory, and being officially announced by email.

    From my point of view, it was a day without email anyway while I moved up main machines several -pX releases. Not a real problem, but yet another reason to teach

    • 1. It takes time to prepare security advisories. The security-officer team (of which I am not a member) likes to check facts and test things before issuing them.

      2. Note that this happened over a weekend.

      3. The timing of events was largely driven by public disclosure of a vulnerability.

      From where I stand (release engineering team) the security-officer (Jacques Vidrine) and his team did a pretty darned good job under the circumstances. Greg Shapiro of Sendmail, Inc. helped by committing the appropriat
  • First start with the tutorial here [freebsddiary.org]

    There is only one change needed: after getting sendmail built and installed, and my sendmail.cf set up from the bsd-4.4 default cm file with M4, local delivery wouldn't work, and gave this error:

    stat=Deferred: local mailer (/usr/libexec/mail.local) exited with EX_TEMPFAIL

    You fix this problem with:

    chown root /usr/libexec/mail.local
    chmod u+s /usr/libexec/mail.local
  • Exim (Score:3, Insightful)

    by phaze3000 ( 204500 ) on Monday March 31, 2003 @04:09AM (#5630201) Homepage
    For those out there looking to replace sendmail, I suggest Exim [exim.org].
    It's extremely stable (we've been running it on our mail cluster for 326 days now with 0 seconds of downtime) and unlike sendmail it doesn't have a config file that looks like line noise.

I have hardly ever known a mathematician who was capable of reasoning. -- Plato

Working...