Bugtraq mailing list archives

Re: [TL-Security-Announce] Sendmail-8.11.2-5 TLSA2001003-1


From: Kris Kennaway <kris () OBSECURITY ORG>
Date: Fri, 23 Feb 2001 13:34:36 -0800

On Thu, Feb 22, 2001 at 02:09:35PM -0800, security () TURBOLINUX COM wrote:
   Sendmail, launched with the -bt command-line switch, enters its special
   "address test" mode. Under these conditions, it is vulnerable to a
   segmentation fault which can occur when trying to set a class in ad-
   dress test mode due to a negative array index.

2. Impact

   A user can gain root privileges.

This was proven to be wrong - this bug is not believed to have any
security impact.

Kris

Attachment: _bin
Description:


Current thread: