Sendmail Prescan() Variant Remote Buffer Overrun Vulnerability
BID:8641
Info
Sendmail Prescan() Variant Remote Buffer Overrun Vulnerability
| Bugtraq ID: | 8641 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0694 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 17 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | Discovery is credited to Michal Zalewski <[email protected]>. |
| Vulnerable: |
Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 Turbolinux Turbolinux Workstation 6.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Turbolinux Server 6.5 Turbolinux Turbolinux Server 6.1 Turbolinux Turbolinux Advanced Server 6.0 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 Sun Linux 5.0.7 Sun Cobalt RaQ 550 Sun Cobalt RaQ 4 SGI IRIX 6.5.21 m SGI IRIX 6.5.21 f SGI IRIX 6.5.20 m SGI IRIX 6.5.20 f SGI IRIX 6.5.19 m SGI IRIX 6.5.19 f SGI IRIX 6.5.18 m SGI IRIX 6.5.18 f SGI IRIX 6.5.17 m SGI IRIX 6.5.17 f SGI IRIX 6.5.16 SGI IRIX 6.5.15 Sendmail, Inc Sendmail for NT 3.0.3 Sendmail, Inc Sendmail for NT 3.0.2 Sendmail, Inc Sendmail for NT 3.0.1 Sendmail, Inc Sendmail for NT 3.0 Sendmail, Inc Sendmail for NT 2.6.2 Sendmail, Inc Sendmail for NT 2.6.1 Sendmail, Inc Sendmail for NT 2.6 Sendmail Inc Sendmail Switch 3.0.3 Sendmail Inc Sendmail Switch 3.0.2 Sendmail Inc Sendmail Switch 3.0.1 Sendmail Inc Sendmail Switch 3.0 Sendmail Inc Sendmail Switch 2.2.5 Sendmail Inc Sendmail Switch 2.2.4 Sendmail Inc Sendmail Switch 2.2.3 Sendmail Inc Sendmail Switch 2.2.2 Sendmail Inc Sendmail Switch 2.2.1 Sendmail Inc Sendmail Switch 2.2 Sendmail Inc Sendmail Switch 2.1.5 Sendmail Inc Sendmail Switch 2.1.4 Sendmail Inc Sendmail Switch 2.1.3 Sendmail Inc Sendmail Switch 2.1.2 Sendmail Inc Sendmail Switch 2.1.1 Sendmail Inc Sendmail Switch 2.1 Sendmail Inc Sendmail Pro 8.9.3 Sendmail Inc Sendmail Pro 8.9.2 Sendmail Inc Sendmail Advanced Message Server 1.3 Sendmail Inc Sendmail Advanced Message Server 1.2 Sendmail Consortium Sendmail 8.12.9 Sendmail Consortium Sendmail 8.12.8 Sendmail Consortium Sendmail 8.12.7 Sendmail Consortium Sendmail 8.12.6 Sendmail Consortium Sendmail 8.12.5 Sendmail Consortium Sendmail 8.12.4 Sendmail Consortium Sendmail 8.12.3 Sendmail Consortium Sendmail 8.12.2 Sendmail Consortium Sendmail 8.12.1 Sendmail Consortium Sendmail 8.12 beta7 Sendmail Consortium Sendmail 8.12 beta5 Sendmail Consortium Sendmail 8.12 beta16 Sendmail Consortium Sendmail 8.12 beta12 Sendmail Consortium Sendmail 8.12 beta10 Sendmail Consortium Sendmail 8.12 .0 Sendmail Consortium Sendmail 8.11.6 Sendmail Consortium Sendmail 8.11.5 Sendmail Consortium Sendmail 8.11.4 Sendmail Consortium Sendmail 8.11.3 Sendmail Consortium Sendmail 8.11.2 Sendmail Consortium Sendmail 8.11.1 Sendmail Consortium Sendmail 8.11 Sendmail Consortium Sendmail 8.10.2 Sendmail Consortium Sendmail 8.10.1 Sendmail Consortium Sendmail 8.10 Sendmail Consortium Sendmail 8.9.3 Sendmail Consortium Sendmail 8.9.2 Sendmail Consortium Sendmail 8.9.1 Sendmail Consortium Sendmail 8.9 .0 Sendmail Consortium Sendmail 8.8.8 NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 beta NetBSD NetBSD 1.6 NetBSD NetBSD 1.5.3 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 x86 NetBSD NetBSD 1.5 sh3 NetBSD NetBSD 1.5 NetBSD NetBSD 1.4.3 IBM AIX 4.3.3 IBM AIX 5.2 IBM AIX 5.1 HP HP-UX 11.22 HP HP-UX 11.11 HP HP-UX 11.0 4 HP HP-UX 11.0 Gentoo Linux 1.4 _rc3 Gentoo Linux 1.4 _rc2 Gentoo Linux 1.4 _rc1 Gentoo Linux 1.2 Gentoo Linux 1.1 a Gentoo Linux 0.7 Gentoo Linux 0.5 FreeBSD FreeBSD 5.1 -RELENG FreeBSD FreeBSD 5.1 -RELEASE-p5 FreeBSD FreeBSD 5.0 -RELENG FreeBSD FreeBSD 5.0 -RELEASE-p14 FreeBSD FreeBSD 4.9 -PRERELEASE FreeBSD FreeBSD 4.8 -RELENG FreeBSD FreeBSD 4.8 -RELEASE-p7 FreeBSD FreeBSD 4.7 -RELENG FreeBSD FreeBSD 4.7 -RELEASE-p17 FreeBSD FreeBSD 4.6 -RELENG FreeBSD FreeBSD 4.6 -RELEASE-p20 FreeBSD FreeBSD 4.5 -RELENG FreeBSD FreeBSD 4.5 -RELEASE-p32 FreeBSD FreeBSD 4.4 -RELENG FreeBSD FreeBSD 4.4 -RELEASE-p42 FreeBSD FreeBSD 4.3 -RELENG FreeBSD FreeBSD 4.3 -RELEASE-p38 FreeBSD FreeBSD 4.0 -RELENG FreeBSD FreeBSD 3.0 -RELENG Compaq Tru64 5.1 b PK2 (BL22) Compaq Tru64 5.1 b PK1 (BL1) Compaq Tru64 5.1 b Compaq Tru64 5.1 a PK5 (BL23) Compaq Tru64 5.1 a PK4 (BL21) Compaq Tru64 5.1 a PK3 (BL3) Compaq Tru64 5.1 a PK2 (BL2) Compaq Tru64 5.1 a PK1 (BL1) Compaq Tru64 5.1 a Compaq Tru64 5.1 PK6 (BL20) Compaq Tru64 5.1 PK5 (BL19) Compaq Tru64 5.1 PK4 (BL18) Compaq Tru64 5.1 PK3 (BL17) Compaq Tru64 5.1 Compaq Tru64 4.0 g PK4 (BL22) Compaq Tru64 4.0 g PK3 (BL17) Compaq Tru64 4.0 g Compaq Tru64 4.0 f PK8 (BL22) Compaq Tru64 4.0 f PK7 (BL18) Compaq Tru64 4.0 f PK6 (BL17) Compaq Tru64 4.0 f Apple Mac OS X Server 10.2.6 Apple Mac OS X Server 10.2.5 Apple Mac OS X Server 10.2.4 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X 10.2.6 Apple Mac OS X 10.2.5 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 |
| Not Vulnerable: |
SGI IRIX 6.5.22 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 Sendmail Consortium Sendmail 8.12.10 |
Discussion
Sendmail Prescan() Variant Remote Buffer Overrun Vulnerability
Sendmail is prone to a buffer overrun vulnerability in the prescan() function. This issue is different than the vulnerability described in BID 7230. This vulnerability could permit remote attackers to execute arbitrary code via vulnerable versions of Sendmail.
Sendmail is prone to a buffer overrun vulnerability in the prescan() function. This issue is different than the vulnerability described in BID 7230. This vulnerability could permit remote attackers to execute arbitrary code via vulnerable versions of Sendmail.
Exploit / POC
Sendmail Prescan() Variant Remote Buffer Overrun Vulnerability
Gyan Chawdhary <[email protected]>, has supplied the following local proof of concept exploit:
Gyan Chawdhary <[email protected]>, has supplied the following local proof of concept exploit:
Solution / Fix
Sendmail Prescan() Variant Remote Buffer Overrun Vulnerability
Solution:
The vendor has released Sendmail 8.12.10 to address this issue. Administrators are advised to upgrade if possible. A patch is also available which can be applied to other versions.
Sun have released fixes to address this vulnerability in Sun Linux 5.0.7. Users who are affected by this issue are advised to apply relevant fixes as soon as possible. Please see Sun reference (Sun Linux Support - Sun Linux Patches (Sun)) for further details regarding obtaining and applying appropriate fixes.
HP has released an advisory HPSBUX0309-281 to address this issue. Please see the referenced advisory for more information.
HP has issued an early release patch (t64kit0020132-v40gb22-es-20031001.tar) and a related readme (t64kit0020132-v40gb22-es-20031001.README) to address this issue in Tru64 4.0G systems. On October 22 of 2003, HP released t64v51ab-ix-553-sendmail-ssrt3631.README for Tru64, which contains updated fixes for Tru64 UNIX 5.1B PK2 (BL22), and t64v51ab-ix-586-sendmail-ssrt3631 and t64v51ab-ix-594-sendmail-ssrt3631 for Tru64 UNIX 5.0A. See referenced readmes for further details.
HP has released a revised advisory HPSBUX0309-281 to address this issue. HP has also released an advisory (SSRT3631) for Tru64 UNIX. An advisory corresponding to DUXKIT0020136-V40FB22-ES-20031001 for Tru64 UNIX has also been released. Please see the referenced advisories for further details.
New Tru64 advisories were released October 9, 2003 with new download links for patches. An additional Tru64 advisory (corresponding to T64V51AB21-C0112900-17770-ES-20030402) was also released October 10, 2003 that provides new download links for 5.1A fixes. Another Tru64 advisory (corresponding to T64V40GB17-C0029200-17810-ES-20030403) was released October 13, 2003 that provides new download links for updated 4.0G fixes. HP has released an updated advisory (t64kit0020139-v51b20-es-20031001) for HP Tru64 UNIX 5.1 PK6. Please see the referenced advisories for further information regarding updating and applying fixes.
SGI has released an advisory (20030903-01-P), to address this issue. Users are advised to download and apply a relevant patch as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory. Fixes are linked below.
Conectiva has released an advisory (CLA-2003:742), to address this issue. Users are advised to download and apply a relevant fixes as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory.
Turbolinux has released an advisory (TLSA-2003-52), to address this issue. Users are advised to download and apply a relevant fix as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory.
Yellow Dog Linux has released an advisory (YDU-20030917-2), to address this issue. Users are advised to download and apply a relevant fix as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory. Fixes are linked below.
Gentoo Linux has released an advisory (200309-13) to address this issue for Gentoo Linux users. Users who are running net-mail/sendmail are advised to upgrade to sendmail-8.2.10 by issuing the following commands as root:
emerge sync
emerge sendmail
emerge clean
Immunix has released an advisory (IMNX-2003-7+-021-01), to address this issue. Users are advised to download and apply a relevant fix as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory. Fixes are linked below.
FreeBSD has released an advisory (FreeBSD-SA-03:13.sendmail), to address this issue. Users are advised to download and apply the relevant patch as soon as possible. Further information relating to obtaining and applying appropriate patches is available in the referenced advisory.
Debian has issued fixes for this vulnerability that are listed in advisory [DSA-384-1] (see reference section).
Red Hat has issued fixes, listed in [RHSA-2003:283-01] (see reference section).
OpenPKG has released an advisory (OpenPKG-SA-2003.041) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Conectiva has released an advisory (CLA-2003:746), to address this issue for CLEE 1.0. Users are advised to download and apply a relevant fixes as soon as possible. Please see the referenced advisory for more information.
SuSE has released an advisory SuSE-SA:2003:040 to address this issue. Please see the referenced advisory for more information.
Sun has released an alert for Solaris to address this issue. Affected users are advised to apply an available patch. Sun has also released an alert for
Sun Linux advising disabling sendmail on affected systems. See referenced advisories for additional details.
Apple has released security advisory APPLE-SA-2003-09-22 to address this issue. See referenced advisory for additional details.
IBM has issued an advisory. APARs to address this issue are available.
See the advisory, MSS-OAR-E01-2003:1235.1, in the reference section for complete installation details.
NetBSD has stated versions 1.5 through 1.6.1 are affected by this issue if sendmail is enabled, which is not the default configuration. See referenced advisory for additional details.
HP advisory SSRT3631 revision 2 has been released to address this issue. See referenced advisory for further details regarding obtaining and applying fixes. Additional fixes are available for HP Tru64 UNIX (IX) Internet Express systems that are running sendmail versions 8.9.3 through 8.12.9.
SCO has released a seucrity advisory for OpenLinux (CSSA-2003-036.0) which contains fixes to address this issue. Further information on how to obtain and apply fixes can be found in the referenced advisory.
Revised HP advisory SSRT3631 has released to address this issue.
Sun has released an update to address this in Sun RaQ550. Please see the referenced web page for more information.
IBM is said to have released APARs to address this issue. Further information can be obtained by contacting the vendor.
Revised HP advisory has been released to address this issue.
Sun has released an update to address this in Sun RaQXTR. Please see the referenced web page for more information.
Sun has released an update to address this in Sun Qube3. Please see the referenced web page for more information.
Sun has released an updated RaQ4 fix.
Revised HP advisory HPSBUX0309-281: SSRT3631 Rev.7 has been released to address this issue.
Revised HP advisory HPSBUX0309-281: SSRT3631 Rev.8 has been released to address this issue.
SCO has released a security advisory for OpenServer (SCOSA-2004.11) along with fixes to address this issue. Further information on how to obtain and apply fixes can be found in the referenced advisory.
Sun Solaris 8_sparc
IBM AIX 5.1
Sun Solaris 7.0
HP HP-UX 11.0 4
HP HP-UX 11.22
Compaq Tru64 4.0 g
FreeBSD FreeBSD 4.7 -RELENG
Sun Linux 5.0.7
FreeBSD FreeBSD 5.1 -RELENG
FreeBSD FreeBSD 5.1 -RELEASE-p5
SGI IRIX 6.5.16
SGI IRIX 6.5.17 m
SGI IRIX 6.5.19 f
SGI IRIX 6.5.20 f
SGI IRIX 6.5.20 m
SGI IRIX 6.5.21 m
Sendmail Consortium Sendmail 8.10
Sendmail Consortium Sendmail 8.10.1
Sendmail Consortium Sendmail 8.11
Sendmail Consortium Sendmail 8.11.2
Sendmail Consortium Sendmail 8.11.3
Sendmail Consortium Sendmail 8.11.4
Sendmail Consortium Sendmail 8.11.5
Sendmail Consortium Sendmail 8.11.6
Sendmail Consortium Sendmail 8.12 beta12
Sendmail Consortium Sendmail 8.12 beta5
Sendmail Consortium Sendmail 8.12.1
Sendmail Consortium Sendmail 8.12.3
Sendmail Consortium Sendmail 8.12.7
Sendmail Consortium Sendmail 8.12.8
Sendmail Consortium Sendmail 8.9 .0
Sendmail Consortium Sendmail 8.9.2
Sendmail Consortium Sendmail 8.9.3
Solution:
The vendor has released Sendmail 8.12.10 to address this issue. Administrators are advised to upgrade if possible. A patch is also available which can be applied to other versions.
Sun have released fixes to address this vulnerability in Sun Linux 5.0.7. Users who are affected by this issue are advised to apply relevant fixes as soon as possible. Please see Sun reference (Sun Linux Support - Sun Linux Patches (Sun)) for further details regarding obtaining and applying appropriate fixes.
HP has released an advisory HPSBUX0309-281 to address this issue. Please see the referenced advisory for more information.
HP has issued an early release patch (t64kit0020132-v40gb22-es-20031001.tar) and a related readme (t64kit0020132-v40gb22-es-20031001.README) to address this issue in Tru64 4.0G systems. On October 22 of 2003, HP released t64v51ab-ix-553-sendmail-ssrt3631.README for Tru64, which contains updated fixes for Tru64 UNIX 5.1B PK2 (BL22), and t64v51ab-ix-586-sendmail-ssrt3631 and t64v51ab-ix-594-sendmail-ssrt3631 for Tru64 UNIX 5.0A. See referenced readmes for further details.
HP has released a revised advisory HPSBUX0309-281 to address this issue. HP has also released an advisory (SSRT3631) for Tru64 UNIX. An advisory corresponding to DUXKIT0020136-V40FB22-ES-20031001 for Tru64 UNIX has also been released. Please see the referenced advisories for further details.
New Tru64 advisories were released October 9, 2003 with new download links for patches. An additional Tru64 advisory (corresponding to T64V51AB21-C0112900-17770-ES-20030402) was also released October 10, 2003 that provides new download links for 5.1A fixes. Another Tru64 advisory (corresponding to T64V40GB17-C0029200-17810-ES-20030403) was released October 13, 2003 that provides new download links for updated 4.0G fixes. HP has released an updated advisory (t64kit0020139-v51b20-es-20031001) for HP Tru64 UNIX 5.1 PK6. Please see the referenced advisories for further information regarding updating and applying fixes.
SGI has released an advisory (20030903-01-P), to address this issue. Users are advised to download and apply a relevant patch as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory. Fixes are linked below.
Conectiva has released an advisory (CLA-2003:742), to address this issue. Users are advised to download and apply a relevant fixes as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory.
Turbolinux has released an advisory (TLSA-2003-52), to address this issue. Users are advised to download and apply a relevant fix as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory.
Yellow Dog Linux has released an advisory (YDU-20030917-2), to address this issue. Users are advised to download and apply a relevant fix as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory. Fixes are linked below.
Gentoo Linux has released an advisory (200309-13) to address this issue for Gentoo Linux users. Users who are running net-mail/sendmail are advised to upgrade to sendmail-8.2.10 by issuing the following commands as root:
emerge sync
emerge sendmail
emerge clean
Immunix has released an advisory (IMNX-2003-7+-021-01), to address this issue. Users are advised to download and apply a relevant fix as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory. Fixes are linked below.
FreeBSD has released an advisory (FreeBSD-SA-03:13.sendmail), to address this issue. Users are advised to download and apply the relevant patch as soon as possible. Further information relating to obtaining and applying appropriate patches is available in the referenced advisory.
Debian has issued fixes for this vulnerability that are listed in advisory [DSA-384-1] (see reference section).
Red Hat has issued fixes, listed in [RHSA-2003:283-01] (see reference section).
OpenPKG has released an advisory (OpenPKG-SA-2003.041) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Conectiva has released an advisory (CLA-2003:746), to address this issue for CLEE 1.0. Users are advised to download and apply a relevant fixes as soon as possible. Please see the referenced advisory for more information.
SuSE has released an advisory SuSE-SA:2003:040 to address this issue. Please see the referenced advisory for more information.
Sun has released an alert for Solaris to address this issue. Affected users are advised to apply an available patch. Sun has also released an alert for
Sun Linux advising disabling sendmail on affected systems. See referenced advisories for additional details.
Apple has released security advisory APPLE-SA-2003-09-22 to address this issue. See referenced advisory for additional details.
IBM has issued an advisory. APARs to address this issue are available.
See the advisory, MSS-OAR-E01-2003:1235.1, in the reference section for complete installation details.
NetBSD has stated versions 1.5 through 1.6.1 are affected by this issue if sendmail is enabled, which is not the default configuration. See referenced advisory for additional details.
HP advisory SSRT3631 revision 2 has been released to address this issue. See referenced advisory for further details regarding obtaining and applying fixes. Additional fixes are available for HP Tru64 UNIX (IX) Internet Express systems that are running sendmail versions 8.9.3 through 8.12.9.
SCO has released a seucrity advisory for OpenLinux (CSSA-2003-036.0) which contains fixes to address this issue. Further information on how to obtain and apply fixes can be found in the referenced advisory.
Revised HP advisory SSRT3631 has released to address this issue.
Sun has released an update to address this in Sun RaQ550. Please see the referenced web page for more information.
IBM is said to have released APARs to address this issue. Further information can be obtained by contacting the vendor.
Revised HP advisory has been released to address this issue.
Sun has released an update to address this in Sun RaQXTR. Please see the referenced web page for more information.
Sun has released an update to address this in Sun Qube3. Please see the referenced web page for more information.
Sun has released an updated RaQ4 fix.
Revised HP advisory HPSBUX0309-281: SSRT3631 Rev.7 has been released to address this issue.
Revised HP advisory HPSBUX0309-281: SSRT3631 Rev.8 has been released to address this issue.
SCO has released a security advisory for OpenServer (SCOSA-2004.11) along with fixes to address this issue. Further information on how to obtain and apply fixes can be found in the referenced advisory.
Sun Solaris 8_sparc
-
Sun 110615-10
http://sunsolve.sun.com
IBM AIX 5.1
-
IBM IY48658
http://www-1.ibm.com/support/
Sun Solaris 7.0
-
Sun 107684-10
http://sunsolve.sun.com
HP HP-UX 11.0 4
-
HP sendmail.893.11.00.r4.gz
ftp://sendmail:[email protected]/sendmail.893.11.00.r4.gz
HP HP-UX 11.22
-
HP sendmail.811.11.22.r5.gz
ftp://sendmail:[email protected]/sendmail.811.11.22.r5.gz
Compaq Tru64 4.0 g
-
HP t64kit0020132-v40gb22-es-20031001.tar
http://ftp.support.compaq.com/patches/public/unix/v4.0g/t64kit0020132- v40gb22-es-20031001.tar
FreeBSD FreeBSD 4.7 -RELENG
-
FreeBSD sendmail.patch
sendmail.patch has been verified to apply to FreeBSD 5.1, 4.8,and 4.7 systems.
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:13/sendmail.patch -
FreeBSD sendmail.patch.asc
sendmail.patch has been verified to apply to FreeBSD 5.1, 4.8,and 4.7 systems.
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:13/sendmail.patch .asc
Sun Linux 5.0.7
-
Sun sendmail-8.11.6-27.72.i386.rpm
ftp://ftp.cobalt.sun.com/pub/products/sunlinux/5.0/en/updates/i386/RPM S/sendmail-8.11.6-27.72.i386.rpm -
Sun sendmail-cf-8.11.6-27.72.i386.rpm
ftp://ftp.cobalt.sun.com/pub/products/sunlinux/5.0/en/updates/i386/RPM S/sendmail-cf-8.11.6-27.72.i386.rpm -
Sun sendmail-devel-8.11.6-27.72.i386.rpm
ftp://ftp.cobalt.sun.com/pub/products/sunlinux/5.0/en/updates/i386/RPM S/sendmail-devel-8.11.6-27.72.i386.rpm -
Sun sendmail-doc-8.11.6-27.72.i386.rpm
ftp://ftp.cobalt.sun.com/pub/products/sunlinux/5.0/en/updates/i386/RPM S/sendmail-doc-8.11.6-27.72.i386.rpm
FreeBSD FreeBSD 5.1 -RELENG
-
FreeBSD sendmail.patch
sendmail.patch has been verified to apply to FreeBSD 5.1, 4.8,and 4.7 systems.
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:13/sendmail.patch -
FreeBSD sendmail.patch.asc
sendmail.patch has been verified to apply to FreeBSD 5.1, 4.8,and 4.7 systems.
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:13/sendmail.patch .asc
FreeBSD FreeBSD 5.1 -RELEASE-p5
-
FreeBSD sendmail.patch
sendmail.patch has been verified to apply to FreeBSD 5.1, 4.8,and 4.7 systems.
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:13/sendmail.patch -
FreeBSD sendmail.patch.asc
sendmail.patch has been verified to apply to FreeBSD 5.1, 4.8,and 4.7 systems.
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:13/sendmail.patch .asc
SGI IRIX 6.5.16
SGI IRIX 6.5.17 m
SGI IRIX 6.5.19 f
SGI IRIX 6.5.20 f
SGI IRIX 6.5.20 m
SGI IRIX 6.5.21 m
Sendmail Consortium Sendmail 8.10
-
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.10.1
-
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.11
-
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.11.2
-
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.11.3
-
S.u.S.E. sendmail-8.11.3-112.i386.rpm
SuSE-7.2.
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n1/sendmail-8.11.3-112.i38 6.rpm -
S.u.S.E. sendmail-tls-8.11.3-116.i386.rpm
SuSE-7.2.
ftp://ftp.suse.com/pub/suse/i386/update/7.2/sec2/sendmail-tls-8.11.3-1 16.i386.rpm -
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.11.4
-
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html -
TurboLinux sendmail-8.11.6-12.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/sendmail-8.11.6-12.i586.rpm -
TurboLinux sendmail-cf-8.11.6-12.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/sendmail-cf-8.11.6-12.i586.rpm -
TurboLinux sendmail-doc-8.11.6-12.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/sendmail-doc-8.11.6-12.i586.rpm
Sendmail Consortium Sendmail 8.11.5
-
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.11.6
-
S.u.S.E. sendmail-8.11.6-126.ppc.rpm
SuSE-7.3, PPC Power PC Platform.
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n1/sendmail-8.11.6-126.ppc. rpm -
S.u.S.E. sendmail-8.11.6-167.i386.rpm
SuSE-7.3.
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n1/sendmail-8.11.6-167.i38 6.rpm -
S.u.S.E. sendmail-8.11.6-67.sparc.rpm
SuSE-7.3, Sparc Platform.
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n1/sendmail-8.11.6-67.spa rc.rpm -
S.u.S.E. sendmail-tls-8.11.6-125.ppc.rpm
SuSE-7.3, PPC Power PC Platform.
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/sec2/sendmail-tls-8.11.6-12 5.ppc.rpm -
S.u.S.E. sendmail-tls-8.11.6-169.i386.rpm
SuSE-7.3.
ftp://ftp.suse.com/pub/suse/i386/update/7.3/sec2/sendmail-tls-8.11.6-1 69.i386.rpm -
S.u.S.E. sendmail-tls-8.11.6-67.sparc.rpm
SuSE-7.3, Sparc Platform.
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/sec2/sendmail-tls-8.11.6- 67.sparc.rpm -
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html -
TurboLinux sendmail-8.11.6-12.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/sendmail-8.11.6-12.i586.rpm -
TurboLinux sendmail-8.11.6-12.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/sendmail-8.11.6-12.i586.rpm -
TurboLinux sendmail-cf-8.11.6-12.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/sendmail-cf-8.11.6-12.i586.rpm -
TurboLinux sendmail-cf-8.11.6-12.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/sendmail-cf-8.11.6-12.i586.rpm -
TurboLinux sendmail-doc-8.11.6-12.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/sendmail-doc-8.11.6-12.i586.rpm -
TurboLinux sendmail-doc-8.11.6-12.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/sendmail-doc-8.11.6-12.i586.rpm
Sendmail Consortium Sendmail 8.12 beta12
-
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.12 beta5
-
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.12.1
-
Mandrake sendmail-8.12.1-4.5mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-cf-8.12.1-4.5mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-devel-8.12.1-4.5mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-doc-8.12.1-4.5mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Sendmail Consortium parse8.359.2.8
Sendmail Security Patch
http://www.sendmail.org/patches/parse8.359.2.8 -
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.12.3
-
S.u.S.E. sendmail-8.12.3-78.i386.patch.rpm
SuSE-8.0.
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n1/sendmail-8.12.3-78.i386 .patch.rpm -
S.u.S.E. sendmail-devel-8.12.3-78.i386.patch.rpm
SuSE-8.0.
ftp://ftp.suse.com/pub/suse/i386/update/8.0/d4/sendmail-devel-8.12.3-7 8.i386.patch.rpm -
S.u.S.E. sendmail-8.12.3-78.i386.rpm
SuSE-8.0.
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n1/sendmail-8.12.3-78.i386 .rpm -
S.u.S.E. sendmail-devel-8.12.3-78.i386.rpm
SuSE-8.0.
ftp://ftp.suse.com/pub/suse/i386/update/8.0/d4/sendmail-devel-8.12.3-7 8.i386.rpm -
Sendmail Consortium parse8.359.2.8
Sendmail Security Patch
http://www.sendmail.org/patches/parse8.359.2.8 -
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.12.7
-
S.u.S.E. sendmail-8.12.7-77.i586.patch.rpm
SuSE-8.2.
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/sendmail-8.12.7-7 7.i586.patch.rpm -
S.u.S.E. sendmail-devel-8.12.7-77.i586.patch.rpm
SuSE-8.2.
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/sendmail-devel-8. 12.7-77.i586.patch.rpm -
S.u.S.E. sendmail-8.12.7-77.i586.rpm
SuSE-8.2.
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/sendmail-8.12.7-7 7.i586.rpm -
S.u.S.E. sendmail-devel-8.12.7-77.i586.rpm
SuSE-8.2.
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/sendmail-devel-8. 12.7-77.i586.rpm -
Sendmail Consortium parse8.359.2.8
Sendmail Security Patch
http://www.sendmail.org/patches/parse8.359.2.8 -
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.12.8
-
Mandrake sendmail-8.12.9-1.2mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-8.12.9-1.2mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-cf-8.12.9-1.2mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-cf-8.12.9-1.2mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-devel-8.12.9-1.2mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-devel-8.12.9-1.2mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-doc-8.12.9-1.2mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-doc-8.12.9-1.2mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Sendmail Consortium parse8.359.2.8
Sendmail Security Patch
http://www.sendmail.org/patches/parse8.359.2.8 -
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.9 .0
-
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.9.2
-
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html
Sendmail Consortium Sendmail 8.9.3
-
Sendmail Consortium Sendmail 8.12.10
http://www.sendmail.org/8.12.10.html -
TurboLinux sendmail-8.9.3-31.i386.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/AdvancedServ er/6/ja/updates/RPMS/sendmail-8.9.3-31.i386.rpm -
TurboLinux sendmail-8.9.3-31.i386.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/6.1/j a/updates/RPMS/sendmail-8.9.3-31.i386.rpm -
TurboLinux sendmail-8.9.3-31.i386.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/6.5/u pdates/RPMS/sendmail-8.9.3-31.i386.rpm -
TurboLinux sendmail-8.9.3-31.i386.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 6.0/ja/updates/RPMS/sendmail-8.9.3-31.i386.rpm -
TurboLinux sendmail-cf-8.9.3-31.i386.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/AdvancedServ er/6/ja/updates/RPMS/sendmail-cf-8.9.3-31.i386.rpm -
TurboLinux sendmail-cf-8.9.3-31.i386.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/6.1/j a/updates/RPMS/sendmail-cf-8.9.3-31.i386.rpm -
TurboLinux sendmail-cf-8.9.3-31.i386.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/6.5/u pdates/RPMS/sendmail-cf-8.9.3-31.i386.rpm -
TurboLinux sendmail-cf-8.9.3-31.i386.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 6.0/ja/updates/RPMS/sendmail-cf-8.9.3-31.i386.rpm -
TurboLinux sendmail-doc-8.9.3-31.i386.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/AdvancedServ er/6/ja/updates/RPMS/sendmail-doc-8.9.3-31.i386.rpm -
TurboLinux sendmail-doc-8.9.3-31.i386.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/6.1/j a/updates/RPMS/sendmail-doc-8.9.3-31.i386.rpm -
TurboLinux sendmail-doc-8.9.3-31.i386.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/6.5/u pdates/RPMS/sendmail-doc-8.9.3-31.i386.rpm -
TurboLinux sendmail-doc-8.9.3-31.i386.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 6.0/ja/updates/RPMS/sendmail-doc-8.9.3-31.i386.rpm
References
Sendmail Prescan() Variant Remote Buffer Overrun Vulnerability
References:
References:
- AIX Homepage (IBM)
- CERT Advisory CA-2003-25 Buffer Overflow in Sendmail (CERT)
- CLSA-2003:746 (Conectiva)
- Sendmail Homepage (Sendmail Consortium)
- Sun Alert ID: 56860 (Sun Microsystems)
- Sun Alert ID: 56922 (Sun Microsystems)
- Sun Cobalt Qube 3 Patches (Sun)
- Sun Cobalt RaQ 4 Patches (Sun)
- Sun Cobalt RaQ XTR Patches (Sun)
- Sun Cobalt RaQ550 Patches (Sun)
- Sun Linux Support - Sun Linux Patches (Sun)
- t64kit0020132-v40gb22-es-20031001.README (HP)
- t64v51ab-ix-553-sendmail-ssrt3631.README (HP)
- t64v51ab-ix-563-sendmail-ssrt3631.README (HP)
- t64v51ab-ix-586-sendmail-ssrt3631.README (HP)
- t64v51ab-ix-594-sendmail-ssrt3631.README (HP)
- Sendmail 8.12.9 prescan bug (a new one) [CAN-2003-0694] (Michal Zalewski
)