Bugtraq mailing list archives

Re: Sendmail up to 8.9.1 - mail.local instroduces new class of


From: blymn () BAEA COM AU (Brett Lymn)
Date: Tue, 11 Aug 1998 11:19:51 +0930


According to Jonathan Stott:

A better fix would be to use procmail, or /bin/mail, or some other
program for local mail delivery.


A lot of people have been recommending putting procmail in to perform
filtering of mail as an adjunct to sendmail.  I did a quick grep for
the notorious strc{at,py} commands in the procmail source and found
quite a few.  I have not analysed the code but people putting in
filters now to prevent the recent problems with mime et al could be
(I said _could_be_) leaving themselves open for a more subtle exploit
later on via procmail overflows.

--
Brett Lymn, Computer Systems Administrator, British Aerospace Australia
===============================================================================
  And the monks would cry unto them, "Keep the bloody noise down!"
  - Mort, Terry Pratchett.



Current thread: