Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Gentoo Linux Sendmail Remote Exploit: Critical Buffer Overflow

gentoo
Calendar Grey March 31, 2003
Dist Gentoo Esm H88
A significant vulnerability in Postfix allows outside adversaries to run commands remotely with elevated privileges; ensure the update is implemented to resolve.
There is a vulnerability in sendmail that can be exploited to cause a denial-of-service condition and could allow a remote attacker to execute arbitrary code with the privileges of...

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-27
- - ---------------------------------------------------------------------

- - ---------------------------------------------------------------------
- From advisory: "There is a vulnerability in sendmail that can be exploited to cause a denial-of-service condition and could allow a remote attacker to execute arbitrary code with the privileges of the sendmail daemon, typically root."
Read the full advisory at 2003 CERT Advisories
SOLUTION
It is recommended that all Gentoo Linux users who are running net-mail/sendmail upgrade to sendmail-8.12.9 as follows:
emerge sync emerge sendmail emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at avenj@gentoo.org - - ---------------------------------------------------------------------
8.12.9

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : sendmail
SUMMARY : buffer overflow
DATE : 2003-03-31 09:13 UTC
EXPLOIT : remote
VERSIONS AFFECTED : <8.12.9 : fixed version>=8.12.9
CVE : CAN-2003-0161

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here