Debian セキュリティ勧告
DSA-257-1 sendmail -- リモートからの攻撃
- 報告日時:
- 2003-03-04
- 影響を受けるパッケージ:
- sendmail, sendmail-wide
- 危険性:
- あり
- 参考セキュリティデータベース:
- Mitre の CVE 辞書: CVE-2002-1337.
CERT の脆弱性リスト、勧告および付加情報: CA-2003-07, VU#398025. - 詳細:
-
ISS X-Force の Mark Dowd さんにより、sendmail のヘッダ解析 ルーティンにバグが発見されました: sendmail は、非常に長いコメントを 持ったアドレスに遭遇したとき、バッファオーバーフローを起こす 可能性があります。 また、sendmail は、電子メールを転送するときも同様にヘッダを解析する ので、この脆弱性が電子メールを配送しないメールサーバを攻撃する こともありえます。
この問題は、上流では バージョン8.12.8 で、 現安定版 (stable)(woody) ではバージョン 8.12.3-5 で、 旧安定版 (potato) ではバージョン 8.9.3-25 で修正されています。
DSA-257-2: Debian 2.2 (potato) 用にバージョン 8.9.3+3.2W-24、Debian 3.0 (woody) 用にバージョン 8.12.3+3.5Wbeta-5.2 の更新された sendmail-wide パッケージが入手できます。
- 修正:
-
Debian GNU/Linux 2.2 (potato)
- ソース:
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25.diff.gz
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25.dsc
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3.orig.tar.gz
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24.dsc
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24.tar.gz
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25.dsc
- alpha (DEC Alpha):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25_alpha.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_alpha.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_alpha.deb
- arm (ARM):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25_arm.deb
- --
- i386 (Intel IA-32):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25_i386.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_i386.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_i386.deb
- m68k (Motorola 680x0):
- --
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_m68k.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_m68k.deb
- powerpc (PowerPC):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25_powerpc.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_powerpc.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_powerpc.deb
- sparc (Sun SPARC/UltraSPARC):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.9.3-25_sparc.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_sparc.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.9.3+3.2W-24_sparc.deb
Debian GNU/Linux 3.0 (woody)
- ソース:
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5.diff.gz
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5.dsc
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3.orig.tar.gz
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2.dsc
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta.orig.tar.gz
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2.diff.gz
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5.dsc
- アーキテクチャ非依存コンポーネント:
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail-doc_8.12.3-5_all.deb
- alpha (DEC Alpha):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_alpha.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_alpha.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_alpha.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_alpha.deb
- arm (ARM):
- --
- --
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_arm.deb
- --
- hppa (HP PA RISC):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_hppa.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_hppa.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_hppa.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_hppa.deb
- i386 (Intel IA-32):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_i386.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_i386.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_i386.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_i386.deb
- ia64 (Intel IA-64):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_ia64.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_ia64.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_ia64.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_ia64.deb
- m68k (Motorola 680x0):
- --
- --
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_m68k.deb
- --
- mips (MIPS (Big Endian)):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_mips.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_mips.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_mips.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_mips.deb
- mipsel (MIPS (Little Endian)):
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_mipsel.deb
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_mipsel.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_mipsel.deb
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_mipsel.deb
- powerpc (PowerPC):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_powerpc.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_powerpc.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_powerpc.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_powerpc.deb
- s390 (IBM S/390):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_s390.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_s390.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_s390.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_s390.deb
- sparc (Sun SPARC/UltraSPARC):
- http://security.debian.org/pool/updates/main/s/sendmail/sendmail_8.12.3-5_sparc.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_sparc.deb
- http://security.debian.org/pool/updates/main/s/sendmail-wide/sendmail-wide_8.12.3+3.5Wbeta-5.2_sparc.deb
- http://security.debian.org/pool/updates/main/s/sendmail/libmilter-dev_8.12.3-5_sparc.deb