[rock-user] [Security Announcement] sendmail (RLSA-20060322-04)

Daniel Jahre <[email protected]> Wed, 22 Mar 2006 21:02:56 +0100
Newsgroups gmane.linux.distributions.rock.user
Organization ROCK Linux
Message-ID <[email protected]>
This is a ROCK Linux Security Announcement.

Package: curl
Announcement ID: RLSA-20060322-04
Date: 2006-03-22
Affected Distributions: none
Affected Releases: none
Cross References: SUSE-SA:2006:017, CVE-2006-0058
Fixed at trunk revision: 7265

Content of this advisory:
1) Problem Description
2) Solution or Work-Around
3) Special instructions and notes
4) Updateing your source tree
5) Source package update
6) Binary package update

--------------------------------------------------------------------------------

1) Problem Description
The popular MTA sendmail is vulnerable to a race condition when handling
signals.
Under certain circumstances this bug can be exploited by an attacker to
execute commands remotely.
For details please read the full advisory of Sendmail, Inc.
http://www.sendmail.com/company/advisory/index.shtml

2) Solution or Workaround
There is no known Work-Around. Please update this package to version 8.13.6

3) Special instruction and notes
Please restart sendmail after the update.

4) Updateing your source tree
If you are using a subversion checkout of trunk, run:
 svn up

If you are using submaster run,
 sm sync
to merge the update from trunk into your tree

5) Source package update
As a user of an affected distribution you can update this package by
rebuilding it on your machine
run
 rocket updsrc
to update your local sources and
 rocket emerge sendmail
to install the updated package

6) Binary package update
there are no new binary packages available for this package yet.