Updated Sendmail packages are available to fix a vulnerability that
may allow remote attackers to gain root privileges by sending a
carefully crafted message.
[Updated March 18 2003]
Added packages for Red Hat Enterprise Linux ES and Red Hat Enterprise Linux WS.
Sendmail is a widely used Mail Transport Agent (MTA) which is included
in all Red Hat Enterprise Linux distributions.
During a code audit of Sendmail by ISS, a critical vulnerability was
uncovered that affects unpatched versions of Sendmail prior to version
8.12.8. A remote attacker can send a carefully crafted email message
which, when processed by sendmail, causes arbitrary code to be
executed as root.
We are advised that a proof-of-concept exploit is known to exist, but
is not believed to be in the wild.
Since this is a message-based vulnerability, MTAs other than Sendmail
may pass on the carefully crafted message. This means that unpatched
versions of Sendmail inside a network could still be at risk even if
they do not accept external connections directly.
All users are advised to update to these erratum packages which contain
a backported patch to correct this vulnerability.
Red Hat would like to thank Eric Allman for his assistance with this
vulnerability.
| Red Hat Enterprise Linux AS (v. 2.1) |
|
| SRPMS: |
sendmail-8.11.6-24.72.src.rpm
File outdated by: RHSA-2006:0515 |
72f60487c5b227361f61f5eadeb5ba68 |
| |
| IA-32: |
sendmail-8.11.6-24.72.i386.rpm
File outdated by: RHSA-2006:0515 |
9bae14a318df768e74f3e297257df3a8 |
sendmail-cf-8.11.6-24.72.i386.rpm
File outdated by: RHSA-2006:0515 |
3c807c9cafdead1e81545d0bb4596819 |
sendmail-devel-8.11.6-24.72.i386.rpm
File outdated by: RHSA-2006:0515 |
cfbddff8d0a0f3956af394ad7a1c2b91 |
sendmail-doc-8.11.6-24.72.i386.rpm
File outdated by: RHSA-2006:0515 |
02057532ef7ef6d8cde318ec40af552d |
| |
| IA-64: |
sendmail-8.11.6-24.72.ia64.rpm
File outdated by: RHSA-2006:0515 |
388b6dbaa0a7bc38f414f774e23e3205 |
sendmail-cf-8.11.6-24.72.ia64.rpm
File outdated by: RHSA-2006:0515 |
fa19d08659f9894d296015c4437f95cb |
sendmail-devel-8.11.6-24.72.ia64.rpm
File outdated by: RHSA-2006:0515 |
4e929b69dc98a2fc2311b9eab5babb17 |
sendmail-doc-8.11.6-24.72.ia64.rpm
File outdated by: RHSA-2006:0515 |
7fcbbcf60534e50991bfa1e5dc0e3fef |
| |
| Red Hat Enterprise Linux ES (v. 2.1) |
|
| SRPMS: |
sendmail-8.11.6-24.72.src.rpm
File outdated by: RHSA-2006:0515 |
72f60487c5b227361f61f5eadeb5ba68 |
| |
| IA-32: |
sendmail-8.11.6-24.72.i386.rpm
File outdated by: RHSA-2006:0515 |
9bae14a318df768e74f3e297257df3a8 |
sendmail-cf-8.11.6-24.72.i386.rpm
File outdated by: RHSA-2006:0515 |
3c807c9cafdead1e81545d0bb4596819 |
sendmail-devel-8.11.6-24.72.i386.rpm
File outdated by: RHSA-2006:0515 |
cfbddff8d0a0f3956af394ad7a1c2b91 |
sendmail-doc-8.11.6-24.72.i386.rpm
File outdated by: RHSA-2006:0515 |
02057532ef7ef6d8cde318ec40af552d |
| |
| Red Hat Enterprise Linux WS (v. 2.1) |
|
| SRPMS: |
sendmail-8.11.6-24.72.src.rpm
File outdated by: RHSA-2006:0515 |
72f60487c5b227361f61f5eadeb5ba68 |
| |
| IA-32: |
sendmail-8.11.6-24.72.i386.rpm
File outdated by: RHSA-2006:0515 |
9bae14a318df768e74f3e297257df3a8 |
sendmail-cf-8.11.6-24.72.i386.rpm
File outdated by: RHSA-2006:0515 |
3c807c9cafdead1e81545d0bb4596819 |
sendmail-devel-8.11.6-24.72.i386.rpm
File outdated by: RHSA-2006:0515 |
cfbddff8d0a0f3956af394ad7a1c2b91 |
sendmail-doc-8.11.6-24.72.i386.rpm
File outdated by: RHSA-2006:0515 |
02057532ef7ef6d8cde318ec40af552d |
| |
| Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor |
|
| SRPMS: |
sendmail-8.11.6-24.72.src.rpm
File outdated by: RHSA-2006:0515 |
72f60487c5b227361f61f5eadeb5ba68 |
| |
| IA-64: |
sendmail-8.11.6-24.72.ia64.rpm
File outdated by: RHSA-2006:0515 |
388b6dbaa0a7bc38f414f774e23e3205 |
sendmail-cf-8.11.6-24.72.ia64.rpm
File outdated by: RHSA-2006:0515 |
fa19d08659f9894d296015c4437f95cb |
sendmail-devel-8.11.6-24.72.ia64.rpm
File outdated by: RHSA-2006:0515 |
4e929b69dc98a2fc2311b9eab5babb17 |
sendmail-doc-8.11.6-24.72.ia64.rpm
File outdated by: RHSA-2006:0515 |
7fcbbcf60534e50991bfa1e5dc0e3fef |
| |
(The unlinked packages above are only available from the Red Hat Network)
|