Home > Security > Advisories

Advisories

Mandriva Advisories

Package name sendmail
Date August 31st, 2001
Advisory ID MDKSA-2001:075
Affected versions 7.2, 8.0
Synopsis Updated sendmail packages fix input validation vulnerability

Problem Description

An input validation error exists in sendmail that may allow local users
to write arbitrary data to process memory. This could possibly allow
the execute of code or commands with elevated privileges and may also
allow a local attacker to gain access to the root account.

Updated Packages

Mandrakelinux 7.2

 2c2ebc4afbe6efc4096d3794ae96ba63  7.2/RPMS/sendmail-8.11.0-3.1mdk.i586.rpm
ce746300c402f37cf0d03271a7e55a41  7.2/RPMS/sendmail-cf-8.11.0-3.1mdk.i586.rpm
2137a5294aa63f20e9ff03e97c84bd01  7.2/RPMS/sendmail-doc-8.11.0-3.1mdk.i586.rpm
e63563290213bdfc2e1396ba6fb52aec  7.2/SRPMS/sendmail-8.11.0-3.1mdk.src.rpm

Mandrakelinux 8.0

 9ff57477c98a364588fa7a5ed95750b5  8.0/RPMS/sendmail-8.11.6-1.1mdk.i586.rpm
7c53b2aa7fc6105892ddededf4e31898  8.0/RPMS/sendmail-cf-8.11.6-1.1mdk.i586.rpm
e3d814078cacf5e2cc2c40c2b104100e  8.0/RPMS/sendmail-doc-8.11.6-1.1mdk.i586.rpm
68c2ea65734dd84c67cb3941213e6fb4  8.0/SRPMS/sendmail-8.11.6-1.1mdk.src.rpm

Mandrakelinux 8.0/PPC

 5eba1e225c9a3e88cca42f1b9488cfbe  ppc/8.0/RPMS/sendmail-8.11.6-1.1mdk.ppc.rpm
c05cb59430bff005ecdbfdf944fa8a38  ppc/8.0/RPMS/sendmail-cf-8.11.6-1.1mdk.ppc.rpm
c81fd2d494ef6f9c0f957ae186b08f7e  ppc/8.0/RPMS/sendmail-doc-8.11.6-1.1mdk.ppc.rpm
c10d3fae9f2d3b2ee0cf579baf22d89e  ppc/8.0/SRPMS/sendmail-8.11.6-1.1mdk.src.rpm

References

http://online.securityfocus.com/bid/3163

Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

                rpm --checksig package.rpm
                

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.