Emergency 1.22 due to possible buffer overflow vulnerability ...

Davide Libenzi <[email protected]> Wed, 12 Oct 2005 15:00:29 -0700 (PDT)
Newsgroups gmane.mail.xmail.announce,gmane.mail.xmail.general
Message-ID <[email protected]>

There is a possible buffer overflow vulnerability in all versions of XMail 
previous to 1.22. This does not affect the server itself, but the XMail's 
sendmail binary. Since many runs the XMail's sendmail as suid root, the 
issue can be critical, even if not easily exploitable w/out knowing the 
server setup. I'd suggest everyone to update to 1.22 ASAP:

http://www.xmailserver.org



PS: Mitre has assigned CAN-2005-2943 to this issue.


- Davide