SecurityFocus.com: Return to sender? (Is it time to switch to a Sendmail alternative?)
Sep 09, 2001, 23:48 (26 Talkback[s])
(Other stories by Jon Lasser)
"The recent Sendmail local root exploit must have
supporters of alternative SMTP servers chuckling. I won't be
surprised if this exploit is cited by many as another reason to
switch from Sendmail to Postfix or qmail. I don't buy those
arguments, but there are reasons for some sites to consider an
alternative.
The new hole is straightforward enough: improper parameters can
be passed by local users to the debug command, which can result in
elevated privileges. This is the first serious security flaw in
Sendmail since 1997, according to reports, and as a local root
exploit it is to my mind a member of the third most serious class
of exploits. I consider both remote root and remote user exploits
to be more serious, because they subvert authentication, while
local root exploits only defeat limits on authorization.
The problem is somewhat reminiscent of the Sendmail exploit used
by the Morris worm, in that it exploits Sendmail's debug mode.
(Incidentally, my last column incorrectly identified that worm as
the first: I had intended to say only that it was the first
Internet worm. Researchers at Xerox PARC had experimented with
worms long before Robert T. Morris wrote his.)"
Complete Story
Related Stories:
- Five Mandrake Linux Security Update Advisories: fetchmail, xli, WindowMaker, sendmail, xinetd(Sep 02, 2001)
- Caldera Security Advisory: sendmail instant root exploit(Aug 24, 2001)
- SuSE Security Announcement: sendmail (SuSE-SA:2001:028)(Aug 23, 2001)
- Linux Journal: Securing Sendmail with TLS(Aug 18, 2001)
- TurboLinux: Retraction of Impact Statement in Sendmail Security Advisory
(May 13, 2001)
- Linux Journal: Sendmail Setup for Your Home Network(Apr 19, 2001)
- Unix Insider: Setting up sendmail on a firewall, Part 1(Mar 11, 2001)
- TurboLinux Security Announcement: Sendmail: All versions previous to 8.11.2-5(Feb 22, 2001)
- Upside: Open source stalwart Sendmail looks to wireless for profits(Dec 25, 2000)
- ComputerWorld: Sendmail buys Nascent to beef up UM capabilities(Dec 20, 2000)
- osOpinion: UNIX Sendmail vs. Exchange 2000(Dec 05, 2000)
- Security Portal: Postfix - The Sendmail Replacement, Part II(Nov 22, 2000)