Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
BID:17192
Info
Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
| Bugtraq ID: | 17192 |
| Class: | Race Condition Error |
| CVE: |
CVE-2006-0058 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 22 2006 12:00AM |
| Updated: | Sep 22 2007 12:00AM |
| Credit: | Discovered by Mark Dowd. |
| Vulnerable: |
Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 2.0 Trend Micro InterScan VirusWall 8.0 Trend Micro InterScan VirusWall 7.0 SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 10.0_x86 Sun Solaris 10 Sun Cobalt RaQ XTR Sun Cobalt RaQ 550 Sun Cobalt RaQ 4 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux -current SGI ProPack 3.0 SP6 SGI IRIX 6.5.29 SGI IRIX 6.5.28 SGI IRIX 6.5.27 SGI IRIX 6.5.26 SGI IRIX 6.5.25 SGI IRIX 6.5.24 m SGI IRIX 6.5.24 SGI IRIX 6.5.23 m SGI IRIX 6.5.23 SGI IRIX 6.5.22 m SGI IRIX 6.5.22 SGI IRIX 6.5.21 m SGI IRIX 6.5.21 f SGI IRIX 6.5.21 SGI IRIX 6.5.20 m SGI IRIX 6.5.20 f SGI IRIX 6.5.20 SGI IRIX 6.5.19 m SGI IRIX 6.5.19 f SGI IRIX 6.5.19 Sendmail Consortium Sendmail 8.13.5 Sendmail Consortium Sendmail 8.13.4 Sendmail Consortium Sendmail 8.13.3 Sendmail Consortium Sendmail 8.12.11 Sendmail Consortium Sendmail 8.12.10 Sendmail Consortium Sendmail 8.12.9 Sendmail Consortium Sendmail 8.12.8 Sendmail Consortium Sendmail 8.12.7 Sendmail Consortium Sendmail 8.12.6 Sendmail Consortium Sendmail 8.12.5 Sendmail Consortium Sendmail 8.12.4 Sendmail Consortium Sendmail 8.12.3 Sendmail Consortium Sendmail 8.12.2 Sendmail Consortium Sendmail 8.12.1 Sendmail Consortium Sendmail 8.12 beta7 Sendmail Consortium Sendmail 8.12 beta5 Sendmail Consortium Sendmail 8.12 beta16 Sendmail Consortium Sendmail 8.12 beta12 Sendmail Consortium Sendmail 8.12 beta10 Sendmail Consortium Sendmail 8.12 .0 Sendmail Consortium Sendmail 8.11.7 Sendmail Consortium Sendmail 8.11.6 Sendmail Consortium Sendmail 8.11.5 Sendmail Consortium Sendmail 8.11.4 Sendmail Consortium Sendmail 8.11.3 Sendmail Consortium Sendmail 8.11.2 Sendmail Consortium Sendmail 8.11.1 Sendmail Consortium Sendmail 8.11 Sendmail Consortium Sendmail 8.10.2 Sendmail Consortium Sendmail 8.10.1 Sendmail Consortium Sendmail 8.10 Sendmail Consortium Sendmail 8.9.3 Sendmail Consortium Sendmail 8.9.2 Sendmail Consortium Sendmail 8.9.1 Sendmail Consortium Sendmail 8.9 .0 Sendmail Consortium Sendmail 8.8.8 SCO Unixware 7.1.4 SCO Unixware 7.1.3 SCO Open Server 6.0 S.u.S.E. UnitedLinux 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Redhat Linux 9.0 i386 Redhat Linux 7.3 i386 Redhat Fedora Core5 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 OpenPKG OpenPKG 2.5 OpenPKG OpenPKG 2.4 OpenPKG OpenPKG 2.3 OpenBSD OpenBSD 2.9 OpenBSD OpenBSD 2.8 OpenBSD OpenBSD 2.7 OpenBSD OpenBSD 2.6 OpenBSD OpenBSD 2.5 OpenBSD OpenBSD 2.4 OpenBSD OpenBSD 2.3 OpenBSD OpenBSD 2.2 OpenBSD OpenBSD 2.1 OpenBSD OpenBSD 2.0 OpenBSD OpenBSD 3.8 OpenBSD OpenBSD 3.7 OpenBSD OpenBSD 3.6 OpenBSD OpenBSD 3.5 OpenBSD OpenBSD 3.4 OpenBSD OpenBSD 3.3 OpenBSD OpenBSD 3.2 OpenBSD OpenBSD 3.1 OpenBSD OpenBSD 3.0 Nortel Networks W-NMS-UMTS 4.2 Nortel Networks W-NMS-GPRS 4.2 Nortel Networks W-NMS-CNM 1.0 NetBSD NetBSD 2.1 NetBSD NetBSD 2.0.3 NetBSD NetBSD 2.0.2 NetBSD NetBSD 2.0.1 NetBSD NetBSD 2.0 NetBSD NetBSD 1.6.2 NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 beta NetBSD NetBSD 1.6 Navision Financials Server 3.0 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 IBM Hardware Management Console (HMC) 5.2.1 IBM AIX 5.3 L IBM AIX 5.2 L IBM AIX 5.1 L IBM AIX 5.3 IBM AIX 5.2 IBM AIX 5.1 HP Tru64 5.1 B-3 HP Tru64 5.1 B-2 PK4 HP Tru64 5.1 A PK6 HP Tru64 4.0 G PK4 HP Tru64 4.0 F PK8 HP Internet Express 6.5 HP Internet Express 6.4 HP Internet Express 6.3 HP HP-UX 11.23 HP HP-UX 11.11 HP HP-UX 11.0 HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.11 HP HP-UX B.11.04 HP HP-UX B.11.00 Gentoo Linux FreeBSD FreeBSD 6.0 -STABLE FreeBSD FreeBSD 6.0 -RELEASE FreeBSD FreeBSD 5.4 -RELENG FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.4 -PRERELEASE FreeBSD FreeBSD 5.3 -STABLE FreeBSD FreeBSD 5.3 -RELENG FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 5.3 FreeBSD FreeBSD 5.2.1 -RELEASE FreeBSD FreeBSD 5.2 -RELENG FreeBSD FreeBSD 5.2 -RELEASE FreeBSD FreeBSD 5.2 FreeBSD FreeBSD 5.1 -RELENG FreeBSD FreeBSD 5.1 -RELEASE/Alpha FreeBSD FreeBSD 5.1 -RELEASE-p5 FreeBSD FreeBSD 5.1 -RELEASE FreeBSD FreeBSD 5.1 FreeBSD FreeBSD 5.0 -RELENG FreeBSD FreeBSD 5.0 -RELEASE-p14 FreeBSD FreeBSD 5.0 alpha FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 4.11 -STABLE FreeBSD FreeBSD 4.11 -RELENG FreeBSD FreeBSD 4.11 -RELEASE-p3 FreeBSD FreeBSD 4.10 -RELENG FreeBSD FreeBSD 4.10 -RELEASE-p8 FreeBSD FreeBSD 4.10 -RELEASE FreeBSD FreeBSD 4.10 FreeBSD FreeBSD 4.9 -RELENG FreeBSD FreeBSD 4.9 -PRERELEASE FreeBSD FreeBSD 4.9 FreeBSD FreeBSD 4.8 -RELENG FreeBSD FreeBSD 4.8 -RELEASE-p7 FreeBSD FreeBSD 4.8 -PRERELEASE FreeBSD FreeBSD 4.8 FreeBSD FreeBSD 4.7 -STABLE FreeBSD FreeBSD 4.7 -RELENG FreeBSD FreeBSD 4.7 -RELEASE-p17 FreeBSD FreeBSD 4.7 -RELEASE FreeBSD FreeBSD 4.7 FreeBSD FreeBSD 4.6.2 FreeBSD FreeBSD 4.6 -STABLE FreeBSD FreeBSD 4.6 -RELENG FreeBSD FreeBSD 4.6 -RELEASE-p20 FreeBSD FreeBSD 4.6 -RELEASE FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 -STABLEpre2002-03-07 FreeBSD FreeBSD 4.5 -STABLE FreeBSD FreeBSD 4.5 -RELENG FreeBSD FreeBSD 4.5 -RELEASE-p32 FreeBSD FreeBSD 4.5 -RELEASE FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 -STABLE FreeBSD FreeBSD 4.4 -RELENG FreeBSD FreeBSD 4.4 -RELENG FreeBSD FreeBSD 4.4 -RELEASE-p42 FreeBSD FreeBSD 4.4 FreeBSD FreeBSD 4.3 -STABLE FreeBSD FreeBSD 4.3 -RELENG FreeBSD FreeBSD 4.3 -RELEASE-p38 FreeBSD FreeBSD 4.3 -RELEASE FreeBSD FreeBSD 4.3 FreeBSD FreeBSD 4.2 -STABLEpre122300 FreeBSD FreeBSD 4.2 -STABLEpre050201 FreeBSD FreeBSD 4.2 -STABLE FreeBSD FreeBSD 4.2 -RELEASE FreeBSD FreeBSD 4.2 FreeBSD FreeBSD 4.1.1 -STABLE FreeBSD FreeBSD 4.1.1 -RELEASE FreeBSD FreeBSD 4.1.1 FreeBSD FreeBSD 4.1 FreeBSD FreeBSD 4.0 .x FreeBSD FreeBSD 4.0 -RELENG FreeBSD FreeBSD 4.0 alpha FreeBSD FreeBSD 4.0 FreeBSD FreeBSD 3.5.1 -STABLEpre2001-07-20 FreeBSD FreeBSD 3.5.1 -STABLE FreeBSD FreeBSD 3.5.1 -RELEASE FreeBSD FreeBSD 3.5.1 FreeBSD FreeBSD 3.5 x FreeBSD FreeBSD 3.5 -STABLEpre122300 FreeBSD FreeBSD 3.5 -STABLEpre050201 FreeBSD FreeBSD 3.5 -STABLE FreeBSD FreeBSD 3.5 FreeBSD FreeBSD 3.4 x FreeBSD FreeBSD 3.4 FreeBSD FreeBSD 3.3 x FreeBSD FreeBSD 3.3 FreeBSD FreeBSD 3.2 x FreeBSD FreeBSD 3.2 FreeBSD FreeBSD 3.1 x FreeBSD FreeBSD 3.1 FreeBSD FreeBSD 3.0 -RELENG FreeBSD FreeBSD 3.0 FreeBSD FreeBSD 2.2.8 FreeBSD FreeBSD 2.2.6 FreeBSD FreeBSD 2.2.5 FreeBSD FreeBSD 2.2.4 FreeBSD FreeBSD 2.2.3 FreeBSD FreeBSD 2.2.2 FreeBSD FreeBSD 2.2 x FreeBSD FreeBSD 2.2 FreeBSD FreeBSD 2.1.7 .1 FreeBSD FreeBSD 2.1.6 .1 FreeBSD FreeBSD 2.1.6 FreeBSD FreeBSD 2.1.5 FreeBSD FreeBSD 2.1 x FreeBSD FreeBSD 2.1 FreeBSD FreeBSD 2.0.5 FreeBSD FreeBSD 2.0 FreeBSD FreeBSD 1.1.5 .1 FreeBSD FreeBSD 5.4-STABLE FreeBSD FreeBSD 4.10-PRERELEASE FreeBSD FreeBSD 3.x FreeBSD FreeBSD 2.x F-Secure Messaging Security Gateway X200 3.1 F-Secure Messaging Security Gateway P800 3.2.4 F-Secure Messaging Security Gateway P600 3.2.4 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Avaya Interactive Response 1.3 Avaya Interactive Response 1.2.1 Avaya Interactive Response Avaya Communication Manager Server S8700 Avaya Communication Manager Server S8500 Avaya Communication Manager Server S8300 Avaya CMS Server 13.0 Avaya CMS Server 12.0 Avaya CMS Server 11.0 Avaya CMS Server 9.0 Avaya CMS Server 13.1 |
| Not Vulnerable: |
Sendmail Consortium Sendmail 8.13.6 |
Discussion
Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
Sendmail is prone to a remote code-execution vulnerability.
Remote attackers may leverage this issue to execute arbitrary code with the privileges of the application, which typically runs as superuser.
Versions prior to Sendmail 8.13.6 are vulnerable to this issue.
Sendmail is prone to a remote code-execution vulnerability.
Remote attackers may leverage this issue to execute arbitrary code with the privileges of the application, which typically runs as superuser.
Versions prior to Sendmail 8.13.6 are vulnerable to this issue.
Exploit / POC
Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Proof-of-concept exploits are available.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Proof-of-concept exploits are available.
Solution / Fix
Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
Solution:
The vendor has released version 8.13.6 to address this issue.
Please see the referenced advisories for more information and fixes.
OpenBSD OpenBSD 3.0
IBM AIX 5.1
HP HP-UX B.11.11
OpenBSD OpenBSD 3.1
HP HP-UX B.11.00
OpenBSD OpenBSD 3.5
OpenBSD OpenBSD 2.3
OpenBSD OpenBSD 2.5
FreeBSD FreeBSD 4.8 -PRERELEASE
FreeBSD FreeBSD 4.8
SCO Unixware 7.1.4
Sendmail Consortium Sendmail 8.11.2
Sendmail Consortium Sendmail 8.12 beta5
Sendmail Consortium Sendmail 8.12.1
Sendmail Consortium Sendmail 8.12.11
Sendmail Consortium Sendmail 8.12.8
Sendmail Consortium Sendmail 8.13.5
Sendmail Consortium Sendmail 8.9.2
Sendmail Consortium Sendmail 8.9.3
Solution:
The vendor has released version 8.13.6 to address this issue.
Please see the referenced advisories for more information and fixes.
OpenBSD OpenBSD 3.0
-
OpenBSD 001_sendmail.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/001_sendmail.patc h
IBM AIX 5.1
-
IBM IY82992
AIX 5.1.0:
http://www.ibm.com/servers/eserver/support/unixservers/aixfixes.html -
IBM sendmail_vu834865.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/sendmail_vu834865.tar.Z
HP HP-UX B.11.11
-
HP PHNE_35484
http://itrc.hp.com
OpenBSD OpenBSD 3.1
-
OpenBSD 001_sendmail.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/001_sendmail.patc h
HP HP-UX B.11.00
-
HP PHNE_35483
http://itrc.hp.com
OpenBSD OpenBSD 3.5
-
OpenBSD 001_sendmail.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/001_sendmail.patc h
OpenBSD OpenBSD 2.3
-
OpenBSD 001_sendmail.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/001_sendmail.patc h
OpenBSD OpenBSD 2.5
-
OpenBSD 001_sendmail.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/001_sendmail.patc h
FreeBSD FreeBSD 4.8 -PRERELEASE
-
FreeBSD sendmail.patch
sendmail.patch has been verified to apply to FreeBSD 5.1, 4.8,and 4.7 systems.
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:13/sendmail.patch -
FreeBSD sendmail.patch.asc
sendmail.patch has been verified to apply to FreeBSD 5.1, 4.8,and 4.7 systems.
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:13/sendmail.patch .asc
FreeBSD FreeBSD 4.8
-
FreeBSD sendmail.patch
sendmail.patch has been verified to apply to FreeBSD 5.1, 4.8,and 4.7 systems.
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:13/sendmail.patch -
FreeBSD sendmail.patch.asc
sendmail.patch has been verified to apply to FreeBSD 5.1, 4.8,and 4.7 systems.
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:13/sendmail.patch .asc
SCO Unixware 7.1.4
-
SCO SCOSA-2006.24
UnixWare 7.1.3, 7.14
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24
Sendmail Consortium Sendmail 8.11.2
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12 beta5
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12.1
-
Mandriva sendmail-8.12.11-1.1.M20mdk.i586.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download -
Mandriva sendmail-8.12.11-1.1.M20mdk.src.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download -
Mandriva sendmail-cf-8.12.11-1.1.M20mdk.i586.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download -
Mandriva sendmail-devel-8.12.11-1.1.M20mdk.i586.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download -
Mandriva sendmail-doc-8.12.11-1.1.M20mdk.i586.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download -
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz -
Slackware sendmail-8.13.6-i486-1.tgz
Slackware 9.1:
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/s endmail-8.13.6-i486-1.tgz -
Slackware sendmail-cf-8.13.6-noarch-1.tgz
Slackware 9.1:
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/s endmail-8.13.6-i486-1.tgz
Sendmail Consortium Sendmail 8.12.11
-
Mandriva sendmail-8.12.11-1.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva sendmail-8.12.11-1.1.C30mdk.src.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva sendmail-8.12.11-1.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva sendmail-cf-8.12.11-1.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva sendmail-cf-8.12.11-1.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva sendmail-devel-8.12.11-1.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva sendmail-devel-8.12.11-1.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva sendmail-doc-8.12.11-1.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva sendmail-doc-8.12.11-1.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
RedHat sendmail-8.12.11-4.26.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/sendmail-8.12.1 1-4.26.legacy.i386.rpm -
RedHat sendmail-cf-8.12.11-4.26.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/sendmail-cf-8.1 2.11-4.26.legacy.i386.rpm -
RedHat sendmail-devel-8.12.11-4.26.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/sendmail-devel- 8.12.11-4.26.legacy.i386.rpm -
RedHat sendmail-doc-8.12.11-4.26.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/sendmail-doc-8. 12.11-4.26.legacy.i386.rpm -
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz -
Slackware sendmail-8.13.6-i486-1.tgz
Slackware 10.0:
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ sendmail-8.13.6-i486-1.tgz -
Slackware sendmail-cf-8.13.6-noarch-1.tgz
Slackware 10.0:
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ sendmail-8.13.6-i486-1.tgz
Sendmail Consortium Sendmail 8.12.8
-
RedHat sendmail-8.12.11-4.24.1.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/sendmail-8.12.1 1-4.24.1.legacy.i386.rpm -
RedHat sendmail-cf-8.12.11-4.24.1.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/sendmail-cf-8.1 2.11-4.24.1.legacy.i386.rpm -
RedHat sendmail-devel-8.12.11-4.24.1.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/sendmail-devel- 8.12.11-4.24.1.legacy.i386.rpm -
RedHat sendmail-doc-8.12.11-4.24.1.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/sendmail-doc-8. 12.11-4.24.1.legacy.i386.rpm -
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz -
Slackware sendmail-8.13.6-i386-1.tgz
Slackware 9.0:
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/s endmail-8.13.6-i386-1.tgz -
Slackware sendmail-cf-8.13.6-noarch-1.tgz
Slackware 9.0:
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/s endmail-cf-8.13.6-noarch-1.tgz
Sendmail Consortium Sendmail 8.13.5
-
RedHat sendmail-8.13.6-0.FC5.1.i386.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-8.13.6-0.FC5.1.ppc.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-8.13.6-0.FC5.1.x86_64.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-cf-8.13.6-0.FC5.1.i386.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-cf-8.13.6-0.FC5.1.ppc.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-cf-8.13.6-0.FC5.1.x86_64.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-debuginfo-8.13.6-0.FC5.1.i386.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-debuginfo-8.13.6-0.FC5.1.ppc.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-debuginfo-8.13.6-0.FC5.1.x86_64.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-devel-8.13.6-0.FC5.1.i386.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-devel-8.13.6-0.FC5.1.ppc.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-devel-8.13.6-0.FC5.1.x86_64.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-doc-8.13.6-0.FC5.1.i386.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-doc-8.13.6-0.FC5.1.ppc.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat sendmail-doc-8.13.6-0.FC5.1.x86_64.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.9.2
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.9.3
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
References
Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
References:
References:
- [ BULLETIN ] Potential Vulnerability in Sendmail 8.12 - VU#834865 (Nortel Networks)
- 001: SECURITY FIX: March 25, 2006 (OpenBSD)
- ASA-2006-074 - sendmail security update (RHSA-2006-0264 & RHSA-2006-0265) (Avaya)
- ASA-2006-078 - Sun Alert Notifications from Sun Weekly Report dated Mar 25, 2006 (Avaya)
- Corrective Service Security FIX - MH00688 (PTF) (IBM)
- Cumulative history and Readme for use with HMC V5 R2 and V5 R2.1 (IBM)
- exploiting_sendmail (rapturesecurity.org)
- F-Secure Security Bulletin FSC-2006-2 (F-Secure)
- HPSBTU02116 SSRT061135 rev.1 - HP Tru64 UNIX and HP Internet Express for Tru64 U (HP)
- RHSA-2006:0264-8 - sendmail security update (RedHat)
- RHSA-2006:0265-9 - sendmail security update (RedHat)
- Sendmail 8.13.6 (Sendmail Consortium)
- Sendmail Homepage (Sendmail Consortium)
- Sendmail MTA Security Vulnerability (Sendmail)
- Sendmail Remote Signal Handling Vulnerability (Internet Security Systems)
- Sun Alert ID: 102262 (Sun)
- Sun Alert ID: 102324 (Sun)
- Technical Cyber Security Alert TA06-081A - Sendmail Race Condition Vulnerability (US-CERT)
- Vulnerability Note VU#834865 - Sendmail contains a race condition (US-CERT)