[xmail] Re: [xmail-announce] Emergency 1.22 due to possible buffer overflow vulnerability ...

2005-10-12 Thread Davide Libenzi
On Thu, 13 Oct 2005, Liron Newman wrote: > Davide Libenzi wrote: > >> On Wed, 12 Oct 2005, Davide Libenzi wrote: >> >> >> >>> There is a possible buffer overflow vulnerability in all versions of XMail >>> previous to 1.22. This does not affect the server itself, but the XMail's >>> sendmail binar

[xmail] Re: [xmail-announce] Emergency 1.22 due to possible buffer overflow vulnerability ...

2005-10-12 Thread Liron Newman
Davide Libenzi wrote: >On Wed, 12 Oct 2005, Davide Libenzi wrote: > > > >>There is a possible buffer overflow vulnerability in all versions of XMail >>previous to 1.22. This does not affect the server itself, but the XMail's >>sendmail binary. Since many runs the XMail's sendmail as suid root,

[xmail] Re: [xmail-announce] Emergency 1.22 due to possible buffer overflow vulnerability ...

2005-10-12 Thread Davide Libenzi
On Wed, 12 Oct 2005, Davide Libenzi wrote: > There is a possible buffer overflow vulnerability in all versions of XMail > previous to 1.22. This does not affect the server itself, but the XMail's > sendmail binary. Since many runs the XMail's sendmail as suid root, the > issue can be critical, ev