Description: | Description:
The remote host is missing updates announced in advisory CLA-2003:614.
Sendmail[1] is a widely used Mail Transfer Agent (MTA).
Michal Zalewski reported[6] a remote vulnerability[5] in sendmail versions 8.12.8 and below. The vulnerability lies in the address parser which performs insufficient bounds checking in certain conditions due to a char to int conversion.
It is believed to be possible for remote attackers to cause a Denial of Service condition and to even execute arbitrary commands with the same permissions under which the sendmail daemon runs, which is root.
The sendmail authors have released a new version[2], 8.12.9, which fixes this vulnerability. They have also made available patches[3] for older versions, which the packages provided via this announcement contain.
Starting with Conectiva Linux 7.0, sendmail is no longer the default mail server and has been replaced with Postfix. But sendmail is still shipped in all Conectiva Linux versions.
Solution: The apt tool can be used to perform RPM package upgrades by running 'apt-get update' followed by 'apt-get upgrade'
http://www.securityspace.com/smysecure/catid.html?in=CLA-2003:614 http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002003
Risk factor : Critical
CVSS Score: 10.0
|