Debians sikkerhedsbulletin

DSA-257-1 sendmail -- fjernudnyttelse

Rapporteret den:
4. mar 2003
Berørte pakker:
sendmail, sendmail-wide
Sårbar:
Ja
Referencer i sikkerhedsdatabaser:
I Mitres CVE-ordbog: CVE-2002-1337.
CERTs noter om sårbarheder, bulletiner og hændelser: CA-2003-07, VU#398025.
Yderligere oplysninger:

Mark Dowd fra ISS X-Force har fundet en fejl i sendmails rutiner til fortolkning af headere: Den buffer kunne løbe over, når rutinen stødte på adresser med meget lange kommentarer. Da sendmail også fortolker headere, når e-mails videresendes, kan denne sårbarhed også ramme mail-servere, der ikke leverer e-mail'en.

Dette er rettet i opstrøms version 8.12.8, version 8.12.3-5 af pakken i Debian GNU/Linux 3.0/woody og version 8.9.3-25 af pakken i Debian GNU/Linux 2.2/potato.

DSA-257-2: Opdaterede sendmail-wide-pakker er tilgængelige i pakkerne med version 8.9.3+3.2W-24 til Debian 2.2 (potato) og version 8.12.3+3.5Wbeta-5.2 til Debian 3.0 (woody).

Rettet i:

Debian GNU/Linux 2.2 (potato)

Kildekode:
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25.diff.gz
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25.dsc
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3.orig.tar.gz
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24.dsc
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24.tar.gz
alpha (DEC Alpha):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25_alpha.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_alpha.deb
arm (ARM):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25_arm.deb
--
i386 (Intel IA-32):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25_i386.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_i386.deb
m68k (Motorola 680x0):
--
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_m68k.deb
powerpc (PowerPC):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25_powerpc.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_powerpc.deb
sparc (Sun SPARC/UltraSPARC):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25_sparc.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_sparc.deb

Debian GNU/Linux 3.0 (woody)

Kildekode:
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5.diff.gz
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5.dsc
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3.orig.tar.gz
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2.dsc
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta.orig.tar.gz
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2.diff.gz
Arkitekturuafhængig komponent:
http://security.debian.org/pool/updates/main/s/sendmail/sendmail-doc_8.12.3-5_all.deb
alpha (DEC Alpha):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_alpha.deb
http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_alpha.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_alpha.deb
arm (ARM):
--
--
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_arm.deb
hppa (HP PA RISC):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_hppa.deb
http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_hppa.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_hppa.deb
i386 (Intel IA-32):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_i386.deb
http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_i386.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_i386.deb
ia64 (Intel IA-64):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_ia64.deb
http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_ia64.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_ia64.deb
m68k (Motorola 680x0):
--
--
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_m68k.deb
mips (MIPS (Big Endian)):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_mips.deb
http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_mips.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_mips.deb
mipsel (MIPS (Little Endian)):
http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_mipsel.deb
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_mipsel.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_mipsel.deb
powerpc (PowerPC):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_powerpc.deb
http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_powerpc.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_powerpc.deb
s390 (IBM S/390):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_s390.deb
http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_s390.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_s390.deb
sparc (Sun SPARC/UltraSPARC):
http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_sparc.deb
http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_sparc.deb
http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_sparc.deb

MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin. (DSA-257-2)