Secunia Logo
 
Debian update for sendmail-wide
Secunia Advisory: SA8616
Release Date: 2003-04-17
Popularity: 6,061 views

Critical:
Extremely critical
Impact: System access
DoS
Where: From remote
Solution Status: Vendor Patch

OS:Debian GNU/Linux 2.x
Debian GNU/Linux 3.0
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0161


Description:
Debian has issued updated packages for sendmail-wide. These fix a vulnerability in the address parsing, which potentially can be exploited to compromise a vulnerable mail server.

For more information:
http://secunia.com/advisories/8446/

Solution:
Updated packages:

-- Debian GNU/Linux 2.2 alias potato --

Source archives:

http://security.debian.org/pool/updat...-wide/sendmail-wide_8.9.3+3.2W-25.dsc
Size/MD5 checksum: 541 17dd53835e894bc4213d2555384aff75
http://security.debian.org/pool/updat...de/sendmail-wide_8.9.3+3.2W-25.tar.gz
Size/MD5 checksum: 1273704 63cd21c58e45810b21601025c164a85e

Alpha architecture:

http://security.debian.org/pool/updat...sendmail-wide_8.9.3+3.2W-25_alpha.deb
Size/MD5 checksum: 302722 8b36867359dd0267d8664b290899ec6b

Intel IA-32 architecture:

http://security.debian.org/pool/updat.../sendmail-wide_8.9.3+3.2W-25_i386.deb
Size/MD5 checksum: 217690 f98998b9467ce368b11a862dbe5d4e82

Motorola 680x0 architecture:

http://security.debian.org/pool/updat.../sendmail-wide_8.9.3+3.2W-25_m68k.deb
Size/MD5 checksum: 202538 e56cc6579ae7da5693047a7e9ceec33e

PowerPC architecture:

http://security.debian.org/pool/updat...ndmail-wide_8.9.3+3.2W-25_powerpc.deb
Size/MD5 checksum: 242694 33217654adca1e26bf9e27b4fb96050e

Sun Sparc architecture:

http://security.debian.org/pool/updat...sendmail-wide_8.9.3+3.2W-25_sparc.deb
Size/MD5 checksum: 236530 32fabe460c63c6fd343d4741104a73f3


-- Debian GNU/Linux 3.0 alias woody --

Source archives:

http://security.debian.org/pool/updat...sendmail-wide_8.12.3+3.5Wbeta-5.4.dsc
Size/MD5 checksum: 738 26af096d7a10d63aec72a0b38982973d
http://security.debian.org/pool/updat...mail-wide_8.12.3+3.5Wbeta-5.4.diff.gz
Size/MD5 checksum: 326292 b98e1e9bb74233e1842a0562912b748d
http://security.debian.org/pool/updat...mail-wide_8.12.3+3.5Wbeta.orig.tar.gz
Size/MD5 checksum: 1870451 4c7036e8042bae10a90da4a84a717963

Alpha architecture:

http://security.debian.org/pool/updat...il-wide_8.12.3+3.5Wbeta-5.4_alpha.deb
Size/MD5 checksum: 440622 d2800104eff39be1a94b94d049e77fc1

ARM architecture:

http://security.debian.org/pool/updat...mail-wide_8.12.3+3.5Wbeta-5.4_arm.deb
Size/MD5 checksum: 369412 d63f3107518282fc892835c5251afdcd

Intel IA-32 architecture:

http://security.debian.org/pool/updat...ail-wide_8.12.3+3.5Wbeta-5.4_i386.deb
Size/MD5 checksum: 328794 139dcce3e908b45be6ecd74531279184

Intel IA-64 architecture:

http://security.debian.org/pool/updat...ail-wide_8.12.3+3.5Wbeta-5.4_ia64.deb
Size/MD5 checksum: 574908 7ebf517265802b0abaf41d3eeca27b6d

HP Precision architecture:

http://security.debian.org/pool/updat...ail-wide_8.12.3+3.5Wbeta-5.4_hppa.deb
Size/MD5 checksum: 413604 9f353dbc5f1c3eca9e34da0e34f227c5

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...ail-wide_8.12.3+3.5Wbeta-5.4_m68k.deb
Size/MD5 checksum: 300726 6b9f6f9c143f2ae0d5e3b95c9e74d90e

Big endian MIPS architecture:

http://security.debian.org/pool/updat...ail-wide_8.12.3+3.5Wbeta-5.4_mips.deb
Size/MD5 checksum: 378324 22c8467712e9da461043110a86c23dcc

Little endian MIPS architecture:

http://security.debian.org/pool/updat...l-wide_8.12.3+3.5Wbeta-5.4_mipsel.deb
Size/MD5 checksum: 380264 ae297336eb7a608f4cdacb3b5cdbf4aa

PowerPC architecture:

http://security.debian.org/pool/updat...-wide_8.12.3+3.5Wbeta-5.4_powerpc.deb
Size/MD5 checksum: 362854 522d8c46a0e8e6b6c143e6e7eac502e6

IBM S/390 architecture:

http://security.debian.org/pool/updat...ail-wide_8.12.3+3.5Wbeta-5.4_s390.deb
Size/MD5 checksum: 354776 62f538f78d8d17519c74064473cad1c2

Sun Sparc architecture:

http://security.debian.org/pool/updat...il-wide_8.12.3+3.5Wbeta-5.4_sparc.deb
Size/MD5 checksum: 355964 01de0e06a7bc0fde26b08b7d84e53246


-- Debian GNU/Linux unstable alias sid --

Fixed in version 8.12.9+3.5Wbeta-1.

Original Advisory:
http://www.debian.org/security/2003/dsa-290


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. ClamAV "cli_check_jpeg_exploit()" Denial of Service Vulnerability // 54 views
2. Linksys WRT160N Cross-Site Scripting Vulnerability // 45 views
3. IBM Rational ClearCase Cross-Site Scripting Vulnerability // 43 views
4. Mozilla Firefox 3 Multiple Vulnerabilities // 41 views
5. Sun Java JDK / JRE Multiple Vulnerabilities // 41 views
6. IBM Rational ClearQuest Multiple Vulnerabilities // 39 views
7. DAHDI "ZT_SPANCONFIG" IOCTL Privilege Escalation Vulnerability // 36 views
8. Debian update for flamethrower // 36 views
9. Zaptel "ZT_SPANCONFIG" IOCTL Privilege Escalation Vulnerabilities // 35 views
10. ASP Portal "ASPPortal.mdb" Database Disclosure Security Issue // 35 views