Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Debian 3.0 Woody DSA 278-2 Critical: Sendmail Buffer Overflow Advisory

debian
Calendar Grey April 4, 2003
Scroller Debian
Debian warns of a critical sendmail buffer overflow flaw, urging users to update affected packages without delay.
This is a major brown paperbag update

Summary

This is a major brown paperbag update. The old packages for the
stable distribution (woody) did not work as expected and you should
only update to the neww packages mentioned in this advisory. The
packages in the old stable distribution (potato) are working
properly. I'm awfully sorry for the inconvenience.

At the moment updated packages are only available for alpha, i386 and sparc.

The original advisory was:

Michal Zalewski discovered a buffer overflow, triggered by a char to
int conversion, in the address parsing code in sendmail, a widely used
powerful, efficient, and scalable mail transport agent. This problem
is potentially remotely exploitable.

For the stable distribution (woody) this problem has been
fixed in version 8.12.3-6.3.

We recommend that you upgrade your sendmail packages.


Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: sendmail

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.