Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 16766 - Remote Sendmail Header Processing Security Vulnerability
Summary: Remote Sendmail Header Processing Security Vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Highest critical (vote)
Assignee: Gentoo Security
URL: http://www.iss.net/issEn/delivery/xfo...
Whiteboard:
Keywords:
: 16836 (view as bug list)
Depends on:
Blocks:
 
Reported: 2003-03-03 15:16 UTC by Bug Hunter
Modified: 2003-03-04 12:02 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bug Hunter 2003-03-03 15:16:44 UTC
From the advisory:

Attackers may remotely exploit this vulnerability to gain "root" or superuser
control of any vulnerable Sendmail server. 

Affected Versions:

Sendmail versions from 5.79 to 8.12.7 are vulnerable

Note: The affected versions of Sendmail commercial, Sendmail open source
running on all platforms are known to be vulnerable.

Description:

The Sendmail remote vulnerability occurs when processing and evaluating
header fields in email collected during an SMTP transaction. Specifically,
when fields are encountered that contain addresses or lists of addresses
(such as the "From" field, "To" field and "CC" field), Sendmail attempts
to semantically evaluate whether the supplied address (or list of addresses)
are valid. This is accomplished using the crackaddr() function, which is
located in the headers.c file in the Sendmail source tree. 

Fix: upgrade to 8.12.8

There is already a bug (#16755) with an ebuild for 8.12.8


Reproducible: Always
Steps to Reproduce:
Comment 1 Grant Goodyear (RETIRED) gentoo-dev 2003-03-03 22:04:49 UTC
Fixed on cvs.  GLSA still needs to be sent out. 
Comment 2 Daniel Ahlberg (RETIRED) gentoo-dev 2003-03-04 05:13:36 UTC
glsa sent. 
Comment 3 Martin Holzer (RETIRED) gentoo-dev 2003-03-04 12:02:28 UTC
*** Bug 16836 has been marked as a duplicate of this bug. ***