----------  Messaggio inoltrato  ----------

Subject: [Security Announce] MDKSA-2002:083 - Updated sendmail 
packages    fix smrsh insecurities
Date: 28 Nov 2002 16:40:53 -0000
From: Mandrake Linux Security Team <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]

________________________________________________________


                Mandrake Linux Security Update Advisory
________________________________________________________


Package name:           sendmail
Advisory ID:            MDKSA-2002:083
Date:                   November 28th, 2002

Affected versions:      7.2, 8.0, 8.1, 8.2, 9.0
________________________________________________________


Problem Description:

 A vulnerability was discovered by zen-parse and Pedram Amini in
 the sendmail MTA.  They found two ways to exploit smrsh, an
 application intended as a replacement for the sh shell for use
 with sendmail; the first by inserting specially formatted
 commands in the ~/.forward file and secondly by calling smrsh
 directly with special options.  These can be exploited to give
 users with no shell account, or those not permitted to execute
 certain programs or commands, the ability to bypass these
 restrictions.
_________________________________________________________


References:

  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-1165
  http://www.sendmail.org/smrsh.adv.txt
_________________________________________________________

...
To upgrade automatically, use MandrakeUpdate.  The verification
 of md5 checksums and GPG signatures is performed automatically
 for you.

If you want to upgrade manually, download the updated package
 from one of our FTP server mirrors and upgrade with "rpm -Fvh
 *.rpm".  A list of FTP mirrors can be obtained from:

  http://www.mandrakesecure.net/en/ftp.php

Please verify the update prior to upgrading to ensure the
 integrity of the downloaded package.  You can do this with the
 command:

  rpm --checksig <filename>

All packages are signed by MandrakeSoft for security.  You can
 obtain the GPG public key of the Mandrake Linux Security Team
 from:

  https://www.mandrakesecure.net/RPM-GPG-KEYS

Please be aware that sometimes it takes the mirrors a few hours
 to update.

You can view other update advisories for Mandrake Linux at:

  http://www.mandrakesecure.net/en/advisories/

MandrakeSoft has several security-related mailing list services
 that anyone can subscribe to.  Information on these lists can
 be obtained by visiting:

  http://www.mandrakesecure.net/en/mlist.php

If you want to report vulnerabilities, please contact

  security_linux-mandrake.com

-------------------------------------------------------
 
bye

miKe
_______________________________________
Slackware 8.1 GNU/Linux 2.4.19 @ hp  Xe3
R.U.#219755 - S.R.U.#705 - R.M.#110932

Rispondere a