[rock-user] [Security Announcement] sendmail (RLSA-20060322-04)
Daniel Jahre <[email protected]> Wed, 22 Mar 2006 21:02:56 +0100
| Newsgroups | gmane.linux.distributions.rock.user |
|---|---|
| Organization | ROCK Linux |
| Message-ID | <[email protected]> |
This is a ROCK Linux Security Announcement. Package: curl Announcement ID: RLSA-20060322-04 Date: 2006-03-22 Affected Distributions: none Affected Releases: none Cross References: SUSE-SA:2006:017, CVE-2006-0058 Fixed at trunk revision: 7265 Content of this advisory: 1) Problem Description 2) Solution or Work-Around 3) Special instructions and notes 4) Updateing your source tree 5) Source package update 6) Binary package update -------------------------------------------------------------------------------- 1) Problem Description The popular MTA sendmail is vulnerable to a race condition when handling signals. Under certain circumstances this bug can be exploited by an attacker to execute commands remotely. For details please read the full advisory of Sendmail, Inc. http://www.sendmail.com/company/advisory/index.shtml 2) Solution or Workaround There is no known Work-Around. Please update this package to version 8.13.6 3) Special instruction and notes Please restart sendmail after the update. 4) Updateing your source tree If you are using a subversion checkout of trunk, run: svn up If you are using submaster run, sm sync to merge the update from trunk into your tree 5) Source package update As a user of an affected distribution you can update this package by rebuilding it on your machine run rocket updsrc to update your local sources and rocket emerge sendmail to install the updated package 6) Binary package update there are no new binary packages available for this package yet.