OpenBSD Journal

sendmail(8) Patch In -stable Fixes Local Snooping Vulnerability

Contributed by pitrh on from the love letters in the sand dept.

For those of you who are still using sendmail(8) on OpenBSD 5.4 or 5.5, it's patch and update time.

The vulnerability known as CVE-2014-3956 could allow local users to interfere with open SMTP connections, and it is strongly advised that any sendmail users out there patch their systems without undue delay.

Patches are available for OpenBSD 5.4 and OpenBSD 5.5 as patch 011 and patch 007 respectively.

It is worth noting that from OpenBSD 5.6 onwards (to be released November 1st, 2014), OpenSD's own OpenSMTPD will be the default MTA.

(Comments are closed)


Comments
  1. By rjc (rjc) rafal.czlonka@gmail.com on

    OpenBSD's even ;^)

    Comments
    1. By Anonymous Coward (65.255.177.102) on

      > OpenBSD's even ;^)

      and why on earth is this old story above the fold about the OpenSSL Stuff. reallly, this site has gotten disconnected from reality.

      Comments
      1. By Sebastian Rother (91.65.156.131) on

        > > OpenBSD's even ;^)
        >
        > and why on earth is this old story above the fold about the OpenSSL Stuff. reallly, this site has gotten disconnected from reality.

        Because the sendmail patches got added to the errata but the OpenSSL patches are not yet linked....?! Just a logical assumption...

      2. By Chris (50.71.129.10) on

        > > OpenBSD's even ;^)
        >
        > and why on earth is this old story above the fold about the OpenSSL Stuff. reallly, this site has gotten disconnected from reality.

        There's a fold?

      3. By Janne Johansson (jj) on http://www.inet6.se

        > > OpenBSD's even ;^)
        >
        > and why on earth is this old story above the fold about the OpenSSL Stuff. reallly, this site has gotten disconnected from reality.

        Sorry if you are disappointed, you will get all your money back.

Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]