Emergency 1.22 due to possible buffer overflow vulnerability ...
Davide Libenzi <[email protected]> Wed, 12 Oct 2005 15:00:29 -0700 (PDT)
| Newsgroups | gmane.mail.xmail.announce,gmane.mail.xmail.general |
|---|---|
| Message-ID | <[email protected]> |
There is a possible buffer overflow vulnerability in all versions of XMail previous to 1.22. This does not affect the server itself, but the XMail's sendmail binary. Since many runs the XMail's sendmail as suid root, the issue can be critical, even if not easily exploitable w/out knowing the server setup. I'd suggest everyone to update to 1.22 ASAP: http://www.xmailserver.org PS: Mitre has assigned CAN-2005-2943 to this issue. - Davide