RE: Sendmail Patch

George Gallen <[email protected]> Fri, 19 Sep 2003 13:38:03 -0400
Newsgroups gmane.linux.redhat.release.enigma
Message-ID <[email protected]>
Unfortunatly, when I try to run:

rpm -Uvh, it gives me:

error: failed dependencies:
        /usr/sbin/alternatives   is needed by sendmail-8.12.8-9.90
        chkconfig >= 1.3 is needed by sendmail-8.12.8-9.90
        libc.so.6(GLIBC_2.3)   is needed by sendmail-8.12.8-9.90
        libcrypto.so.4   is needed by sendmail-8.12.8-9.90
        libdb-4.0.so   is needed by sendmail-8.12.8-9.90
        libhesiod.so.0   is needed by sendmail-8.12.8-9.90
        libssl.so.4   is needed by sendmail-8.12.8-9.90
        libwrap.so.0   is needed by sendmail-8.12.8-9.90  

Is this because 7.2 isn't supported anymore? :(

I'm currently at: Sendmail 8.11.6

Granted, my system isn't open to the internet for port 25, so I should
be ok without the update (until I can try to recompile the source..)

George

>-----Original Message-----
>From: Taylor, ForrestX [mailto:[email protected]]
>Sent: Friday, September 19, 2003 1:08 PM
>To: [email protected]
>Subject: Re: Sendmail Patch
>
>
>[email protected] wrote:
>> Is the Sendmail patch (8.12.8) on the RH website
>> the most current? The Sendmail.org site has the most
>> current as 8.12.10.
>> 
>> Does the RH patch rpm of 8.12.8 include the latest
>> sendmail problem? I noticed the build date was
>> Sept 17 2003, lists two recent bug fixes, but doesn't
>> describe them, just gives the ref#, and sendmail.org
>> site doesn't xref the ref# to problem.
>
>Yes, it is the most recent.  Here is a the information from 
>the advisory:
>
>-----
>Michal Zalewski found a bug in the prescan() function of 
>unpatched Sendmail
>versions prior to 8.12.10. The sucessful exploitation of this 
>bug can lead
>to heap and stack structure overflows.  Although no exploit currently
>exists, this issue is locally exploitable and may also be remotely
>exploitable. The Common Vulnerabilities and Exposures project
>(cve.mitre.org) has assigned the name CAN-2003-0694 to this issue.
>
>Additionally, for Red Hat Linux 8.0 and 9 we have included a fix for a
>potential buffer overflow in ruleset parsing.  This problem is not
>exploitable in the default sendmail configuration; it is 
>exploitable only
>if non-standard rulesets recipient (2), final (4), or mailer-specific
>envelope recipients rulesets are used.  The Common Vulnerabilities and
>Exposures project (cve.mitre.org) has assigned the name 
>CAN-2003-0681 to
>this issue.
>
>All users are advised to update to these erratum packages containing a
>backported patch which corrects these vulnerabilities.
>-----
>
>Notice the last paragraph, which talks about the backported patch.
>
>Forrest
>-- 
>
>
>
>_______________________________________________
>enigma-list mailing list
>[email protected]
>https://www.redhat.com/mailman/listinfo/enigma-list
>