[imp] Sendmail Security Hole

Max Kalika max@the-triumvirate.net
Thu, 19 Oct 2000 13:06:46 -0700 (PDT)


Quoting ibarram@cdcna.com:

> Why not just upgrade sendmail, probably alot easier and you
> will be sure to have the latest (which is always the best in
> this case) sendmail

Because the exploit was not limited to sendmail.  There were many posts on 
bugtraq that used the kernel hole in 2.2.14 with other suid programs.  The 
sendmail developers just put in a workaround -- not the fix.

--mk23