Advertisement
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
Sendmail patch issued for critical security flaw

By Staff writers, ZDNet Australia
September 18, 2003
URL: http://www.zdnet.com.au/news/security/soa/Sendmail-patch-issued-for-critical-security-flaw/0,130061744,120278735,00.htm


A critical vulnerability has been found in Sendmail, the most widely used mail server software.

The vulnerability allows attackers to take control of servers using Sendmail, which is commonly used on Linux, Unix and BSD systems.

The discovery and subsequent disclosure of the security flaw comes one day after serious security problems in the OpenSSH secure shell server software were disclosed. Unlike that discovery, there has been little talk of the vulnerability being exploited prior to the issue of the new Sendmail release.

It's the third time this year that a serious vulnerability has been found in Sendmail software, and the second reported by Michal Zalewski, the researcher that posted the most recent bug.

The earlier bug was found by Internet Security Systems in early March.

Users can upgrade to version 8.12.10, which is not affected by the glitch, or apply a patch.

Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved.
ZDNET is a registered service mark of CBS Interactive. ZDNET Logo is a service mark of CBS Interactive.