Companies mobilise to patch Sendmail

A critical vulnerability in Sendmail, the Internet's most popular mail-server application, has security experts and software companies moving quickly on Monday to convince customers to apply a patch.

The flaw allows an attacker to send a specially formatted e-mail that could take control of a mail server running Sendmail and execute a malicious program. At present, no attack tool that could exploit the vulnerability is known to exist, said Greg Olson, chairman and co-founder of Sendmail, the company that has created a commercial version of the software.

"You have to understand that this is a very arcane security issue," he said. "It has been present in Sendmail code for 15 years and that code has been through multiple inspections."

The flaw--ironically in a Sendmail security function--occurs when the mail program parses an overlong header. The vulnerability was first found in December by security software firm Internet Security Systems. The company notified Sendmail and the National Infrastructure Protection Center, a joint computer crime and security task force, on January 13.

"This vulnerability is especially dangerous because the exploit can be delivered within an e-mail message and the attacker doesn't need any specific knowledge of the target to launch a successful attack," stated an ISS advisory released Monday.

Because the vulnerability is contained in an e-mail message, it will bypass firewalls and many intrusion detection systems, said Dan Ingsvaldson, team leader for ISS's vulnerability research group. Moreover, mail servers--also called mail transport agents (MTAs)--that aren't vulnerable will still forward the flaw-exploiting e-mail message onto its destination.

"The only dependency is that the domain needs to accept e-mail," Ingevaldson said.

The flaw is unrelated to a November break-in at the Sendmail Consortium's Web site.

Several companies, including Red Hat, IBM, SGI, Sun and Hewlett-Packard, released patches Monday. The Sendmail Consortium, the group responsible for development of the open-source Sendmail code, released Sendmail 8.12.8, an updated program that fixes the flaw.

"The key here is to get the word out and get it fixed before hackers get an exploit," said Sendmail's Olson. "You need to contact a lot of people and make sure they understand this is important and apply the patch."

Like this article? Click below to send it to your mobile for free!

Talkback 0 comments


Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay Australian Govt funds IT start-ups
    This week Australia's Federal Government announced it had allocated $3.6 million in funding to 57 local research projects so that they could be commercialised, with many of them being web or IT-related start-ups.
  • Array Google should come clean on datacentres
    It's nice that Google says it has put an effort into making its datacentres more energy efficient, but the search giant's pledges won't mean much until it discloses just how many of the beasties it's actually running.
  • Array US shows what OPEL could have been
    Sprint's WiMAX roll-out in Baltimore will prove the Australian government's decision to worm its way out of the Opel WiMAX contract was a short-sighted, and ultimately damaging, political stunt that has benefited nobody.
  • More blogs »

Tags

Back to top

Featured