Great Circle Associates Firewalls
(October 1993)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Sun sendmail vulnerability
From: Dan . Farmer @ Corp . Sun . COM
Date: Fri, 22 Oct 1993 08:31:35 -0700
To: rens @ imsi . com, firewalls @ GreatCircle . COM
In-reply-to: Rens Troost <rens @ lorax . IMSI . COM> "Sun sendmail vulnerability" (Oct 22, 9:28)

> Does anyone have more info on the sendmail vulnerability announced by
> CERT yesterday?

  Why, as a matter of fact...

The bug is a variation of an older one; basically by manipulating the
headers you can execute a command remotely.  I don't know how your setup
forwards mail, but if you just pump all the mail to a internal spot that
then processes it, I suppose it could be affected (and certainly if you
use sendmail to forward the stuff.)

A couple of other details; as far as I know, when the bug is exploited,
or is attempted, a note will go to the postmaster, so if you see some
suspicious mail (you'd know when you saw it, believe me :-))  I'm not
sure if this is a strictly sun thing, but I suspect we did this one
all by ourselves.  I'll be sending some stuff to berkeley, however,
just to be sure.

 -- d



Follow-Ups:
Indexed By Date Previous: Re: Sun sendmail vulnerability
From: greep @ datatools . com (Steven Tepper)
Next: Re: Sun sendmail vulnerability
From: Leland K. Neely <lkn @ llnl . gov>
Indexed By Thread Previous: Re: Sun sendmail vulnerability
From: Bob Dew <rdew @ alw . nih . gov>
Next: Re: Sun sendmail vulnerability
From: Leland K. Neely <lkn @ llnl . gov>

Google
 
Search Internet Search www.greatcircle.com