Re: Emergency 1.22 due to possible buffer overflow vulnerability ...

Davide Libenzi <[email protected]> Wed, 12 Oct 2005 15:03:49 -0700 (PDT)
Newsgroups gmane.mail.xmail.announce
Message-ID <Pine.LNX.4.63.0510121503010.26823__7665.83672161705$1129155155$gmane$org@localhost.localdomain>
On Wed, 12 Oct 2005, Davide Libenzi wrote:

> There is a possible buffer overflow vulnerability in all versions of XMail
> previous to 1.22. This does not affect the server itself, but the XMail's
> sendmail binary. Since many runs the XMail's sendmail as suid root, the
> issue can be critical, even if not easily exploitable w/out knowing the
> server setup. I'd suggest everyone to update to 1.22 ASAP:

Side note if it wasn't clear. Even the Windows XMail's sendmail is 
affected ...



- Davide