remote buffer overflow in sendmail

"Todd C. Miller" <[email protected]>
Newsgroups gmane.os.openbsd.security.announce
Message-ID <[email protected]>
A buffer overflow has been found in sendmail's envelope comment
processing code which may allow an attacker to gain root privileges.
The bug was discovered by Mark Dowd of ISS X-Force.

For more information, see:
    http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21950
    http://www.sendmail.org/8.12.8.html

As shipped, OpenBSD runs a sendmail that binds only to localhost,
making this a localhost-only hole in the default configuration.
However, any sendmail configuration that accepts incoming mail may
potentially be exploited.

The sendmail in OpenBSD-current has been updated to version 8.12.8.
The 3.1 and 3.2 -stable branches have had a patch applied that fixes
the buffer overflow.  However, because the -stable branches have
the specific vulnerability patched (as opposed to the full 8.12.8
distribution), sendmail on -stable will report the old sendmail version.

Patch for OpenBSD 3.1:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/022_sendmail.patch

Patch for OpenBSD 3.2:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/009_sendmail.patch

Patches for older versions of sendmail may be found at
ftp://ftp.sendmail.org/pub/sendmail/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.