[comp.mail.sendmail] help with sendmail bug

jimj@convex.csd.uwm.edu (James A Jegers) (02/27/91)

    Hello.
       
       I was checking out one of our systems the other day
       and I belive it has the old sendmail bug.
       I looked in the sendmail.cf file for the OW*
       but couldn't find it.  Does this mean I have the older
       version?  Or how do I test to see if this version is safe?


-- 
                       Computing Services Division
		   University of Wisconsin -- Milwaukee
jimj@csd4.csd.uwm.edu    jimj@convex.csd.uwm.edu    jegers@miller.cs.uwm.edu

das@trac2000.ueci.com (David Snyder) (02/27/91)

In article <9779@uwm.edu>, jimj@convex.csd.uwm.edu (James A Jegers) writes:
>        I was checking out one of our systems the other day
>        and I belive it has the old sendmail bug.
>        I looked in the sendmail.cf file for the OW*
>        but couldn't find it.  Does this mean I have the older
>        version?  Or how do I test to see if this version is safe?
> 
After reading this article I deceided to check our version of sendmail.  Well
I'm glad I did, we have sendmail-5.58 and one of the README files specifically
states that this has the ethernet security holes.  We probably didn't worry
much about that at first because we aren't running ethernet, however we will
be running ethernet within the next 4-6 weeks.

Can anyone enlighten me about these security holes and possibly point me in
the right direction for correcting this problem?  Thanks...

DAS
-- 
David A. Snyder @ UE&C - Catalytic in Philadelphia, PA

UUCP:  ..!uunet!trac2000!das     INTERNET:  das@trac2000.ueci.com