xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

Sendmail地址预扫描内存破坏漏洞


发布时间:2003-03-28
更新时间:2003-04-07
严重程度:
威胁程度:远程管理员权限
错误类型:边界检查错误
利用方式:服务器模式

BUGTRAQ ID:7230
CVE(CAN) ID:CAN-2002-0161

受影响系统
Compaq Tru64 4.0 g PK3 (BL17)
Compaq Tru64 4.0 g
Compaq Tru64 4.0 f PK7 (BL18)
Compaq Tru64 4.0 f PK6 (BL17)
Compaq Tru64 4.0 f
Compaq Tru64 4.0 d PK9 (BL17)
Compaq Tru64 4.0 d
Compaq Tru64 4.0 b
Compaq Tru64 5.0 f
Compaq Tru64 5.0 a PK3 (BL17)
Compaq Tru64 5.0 a
Compaq Tru64 5.0 PK4 (BL18)
Compaq Tru64 5.0 PK4 (BL17)
Compaq Tru64 5.0
Compaq Tru64 5.1 b PK1 (BL1)
Compaq Tru64 5.1 b
Compaq Tru64 5.1 a PK3 (BL3)
Compaq Tru64 5.1 a PK2 (BL2)
Compaq Tru64 5.1 a PK1 (BL1)
Compaq Tru64 5.1 a
Compaq Tru64 5.1 PK6 (BL20)
Compaq Tru64 5.1 PK5 (BL19)
Compaq Tru64 5.1 PK4 (BL18)
Compaq Tru64 5.1 PK3 (BL17)
Compaq Tru64 5.1
HP AlphaServer SC
HP AltaVista Firewall Raptor EC
HP AltaVista Firewall AVFW98
HP HP-UX 10.0 1
HP HP-UX 10.0
HP HP-UX 10.1
HP HP-UX 10.8
HP HP-UX 10.9
HP HP-UX 10.10
HP HP-UX 10.16
HP HP-UX 10.20 SIS
HP HP-UX 10.20 Series 800
HP HP-UX 10.20 Series 700
HP HP-UX 10.20
HP HP-UX 10.24
HP HP-UX 10.26
HP HP-UX 10.30
HP HP-UX 10.34
HP HP-UX 11.0 4
HP HP-UX 11.0
HP HP-UX 11.11
HP HP-UX 11.20
HP HP-UX 11.22
HP HP-UX (VVOS) 10.24
HP HP-UX (VVOS) 11.0 4
HP HP-UX (VVOS) 11.0.4
HP Internet Express 5.4
HP Internet Express 5.7
HP Internet Express 5.8
HP Internet Express 5.9
HP Internet Express 6.0
HP MPE/iX 6.0
HP MPE/iX 6.5
HP MPE/iX 7.0
HP MPE/iX 7.5
HP NonStop-UX Whitney
HP NonStop-UX PUMA
HP Tru64 5.1 a PK4 (BL21)
NetBSD NetBSD 1.5
NetBSD NetBSD 1.5.1
NetBSD NetBSD 1.5.2
NetBSD NetBSD 1.5.3
NetBSD NetBSD 1.6
Sendmail Consortium Sendmail 8.9 .0
Sendmail Consortium Sendmail 8.9.1
Sendmail Consortium Sendmail 8.9.2
Sendmail Consortium Sendmail 8.9.3
   + Compaq Tru64 5.0 a PK3 (BL17)
   + Compaq Tru64 5.1 PK5 (BL19)
   + Debian Linux 2.2
   + Debian Linux 2.2 68k
   + Debian Linux 2.2 alpha
   + Debian Linux 2.2 arm
   + Debian Linux 2.2 IA-32
   + Debian Linux 2.2 powerpc
   + Debian Linux 2.2 sparc
   + IBM AIX 4.3.3
   + SGI IRIX 6.5.7 f
   + SGI IRIX 6.5.7 m
   + SGI IRIX 6.5.8 f
   + SGI IRIX 6.5.8 m
   + SGI IRIX 6.5.9 f
   + SGI IRIX 6.5.9 m
   + SGI IRIX 6.5.10 f
   + SGI IRIX 6.5.10 m
   + SGI IRIX 6.5.11 f
   + SGI IRIX 6.5.11 m
   + SGI IRIX 6.5.12 f
   + SGI IRIX 6.5.12 m
   + SGI IRIX 6.5.13 f
   + SGI IRIX 6.5.13 m
   + SGI IRIX 6.5.14 f
   + SGI IRIX 6.5.14 m
   + SGI IRIX 6.5.15 f
   + SGI IRIX 6.5.15 m
   + SGI IRIX 6.5.16 f
   + SGI IRIX 6.5.16 m
   + SGI IRIX 6.5.17 f
   + SGI IRIX 6.5.17 m
   + SGI IRIX 6.5.18 f
   + SGI IRIX 6.5.18 m
   + SGI IRIX 6.5.19
Sendmail Consortium Sendmail 8.10
Sendmail Consortium Sendmail 8.10.1
Sendmail Consortium Sendmail 8.10.2
   + Sun Cobalt Qube3 4000WG
   + Sun Cobalt RaQ 4
   + Sun Cobalt RaQ XTR
   + Sun Cobalt RaQ XTR 3500R
   + Sun Cobalt RaQ4 3001R
Sendmail Consortium Sendmail 8.11
   + Compaq Tru64 5.1
   + Compaq Tru64 5.1 a
   + Compaq Tru64 5.1 b
   + IBM AIX 5.1
   + IBM AIX 5.2
   - MandrakeSoft Linux Mandrake 7.2
   + RedHat Linux 7.0
   + RedHat Linux 7.0 alpha
   + RedHat Linux 7.0 i386
   + RedHat Linux 7.0 sparc
   - S.u.S.E. Linux 7.0
   - S.u.S.E. Linux 7.0 alpha
   - S.u.S.E. Linux 7.0 ppc
   - S.u.S.E. Linux 7.0 sparc
   + SCO Open Server 5.0.4
   + SCO Open Server 5.0.5
   + SCO Open Server 5.0.6
   + SCO Open Server 5.0.6 a
Sendmail Consortium Sendmail 8.11.1
   + Caldera OpenLinux Server 3.1
   + Caldera OpenLinux Workstation 3.1
   + Conectiva Linux 6.0
Sendmail Consortium Sendmail 8.11.2
   + RedHat Linux 7.1
   + RedHat Linux 7.1 alpha
   + RedHat Linux 7.1 i386
   + RedHat Linux 7.1 ia64
   + S.u.S.E. Linux 7.1
   + S.u.S.E. Linux 7.1 alpha
   + S.u.S.E. Linux 7.1 ppc
   + S.u.S.E. Linux 7.1 sparc
   + S.u.S.E. Linux 7.1 x86
Sendmail Consortium Sendmail 8.11.3
   - MandrakeSoft Corporate Server 1.0.1
   - MandrakeSoft Linux Mandrake 8.0
   + S.u.S.E. Linux 7.2
   + S.u.S.E. Linux 7.2 i386
   - Slackware Linux 7.1
Sendmail Consortium Sendmail 8.11.4
   + Conectiva Linux 7.0
   - Slackware Linux 8.0
Sendmail Consortium Sendmail 8.11.5
Sendmail Consortium Sendmail 8.11.6
   + Caldera OpenLinux Server 3.1
   + Caldera OpenLinux Server 3.1.1
   + Caldera OpenLinux Workstation 3.1
   + Caldera OpenLinux Workstation 3.1.1
   + Conectiva Linux 6.0
   + Conectiva Linux 7.0
   + Conectiva Linux 8.0
   + FreeBSD FreeBSD 4.4
   + FreeBSD FreeBSD 4.5
   + FreeBSD FreeBSD 4.5 -RELEASE
   + Immunix Immunix OS 7.0
   + MandrakeSoft Linux Mandrake 8.0
   + MandrakeSoft Linux Mandrake 8.0 ppc
   + MandrakeSoft Linux Mandrake 8.1
   + MandrakeSoft Linux Mandrake 8.1 ia64
   + RedHat Linux 6.2 i386
   + RedHat Linux 7.0 i386
   + RedHat Linux 7.1 i386
   + RedHat Linux 7.2 i386
   + RedHat Linux 7.2 ia64
   + RedHat Linux 7.3 i386
   + S.u.S.E. Linux 7.3
   + S.u.S.E. Linux 7.3 i386
   + S.u.S.E. Linux 7.3 ppc
   + S.u.S.E. Linux 7.3 sparc
   + Sun Cobalt RaQ 550
   + Sun Linux 5.0
   + Sun Linux 5.0.3
Sendmail Consortium Sendmail 8.12 beta7
Sendmail Consortium Sendmail 8.12 beta5
Sendmail Consortium Sendmail 8.12 beta16
Sendmail Consortium Sendmail 8.12 beta12
Sendmail Consortium Sendmail 8.12 beta10
Sendmail Consortium Sendmail 8.12 .0
Sendmail Consortium Sendmail 8.12.1
   + HP MPE/iX 7.0
   + HP MPE/iX 7.5
   + MandrakeSoft Linux Mandrake 8.2
   + MandrakeSoft Linux Mandrake 8.2 ppc
Sendmail Consortium Sendmail 8.12.2
   + Apple MacOS X 10.2 (Jaguar)
   + Apple MacOS X 10.2.1
   + Apple MacOS X 10.2.2
   + Apple MacOS X 10.2.3
   + Apple MacOS X Server 10.2
   + Apple MacOS X Server 10.2.1
   + Apple MacOS X Server 10.2.2
   + Apple MacOS X Server 10.2.3
   + OpenBSD OpenBSD 3.1
Sendmail Consortium Sendmail 8.12.3
   + Debian Linux 3.0
   + Debian Linux 3.0 alpha
   + Debian Linux 3.0 arm
   + Debian Linux 3.0 hppa
   + Debian Linux 3.0 ia-32
   + Debian Linux 3.0 ia-64
   + Debian Linux 3.0 m68k
   + Debian Linux 3.0 mips
   + Debian Linux 3.0 mipsel
   + Debian Linux 3.0 ppc
   + Debian Linux 3.0 s/390
   + Debian Linux 3.0 sparc
   + FreeBSD FreeBSD 4.6
   + S.u.S.E. Linux 8.0
   + S.u.S.E. Linux 8.0 i386
Sendmail Consortium Sendmail 8.12.4
   + OpenBSD OpenBSD 3.2
   + Slackware Linux -current
   + Slackware Linux 8.1
Sendmail Consortium Sendmail 8.12.5
   + OpenBSD OpenBSD 3.2
Sendmail Consortium Sendmail 8.12.6
   + Apple MacOS X 10.2.4
   + FreeBSD FreeBSD 4.7
   + FreeBSD FreeBSD 5.0
   + MandrakeSoft Corporate Server 2.1
   + MandrakeSoft Linux Mandrake 9.0
   + OpenBSD OpenBSD 3.2
   + S.u.S.E. Linux 8.1
Sendmail Consortium Sendmail 8.12.7
   + Slackware Linux 8.1
Sendmail Consortium Sendmail 8.12.8
   + RedHat Linux 8.0 i386
   + RedHat Linux 9.0 i386
Sendmail Inc Sendmail for NT 2.6
Sendmail Inc Sendmail for NT 2.6.1
Sendmail Inc Sendmail for NT 2.6.2
Sendmail Inc Sendmail for NT 3.0
Sendmail Inc Sendmail for NT 3.0.1
Sendmail Inc Sendmail for NT 3.0.2
Sendmail Inc Sendmail for NT 3.0.3
Sendmail Inc Sendmail Switch 2.1
Sendmail Inc Sendmail Switch 2.1.1
Sendmail Inc Sendmail Switch 2.1.2
Sendmail Inc Sendmail Switch 2.1.3
Sendmail Inc Sendmail Switch 2.1.4
Sendmail Inc Sendmail Switch 2.1.5
Sendmail Inc Sendmail Switch 2.2
Sendmail Inc Sendmail Switch 2.2.1
Sendmail Inc Sendmail Switch 2.2.2
Sendmail Inc Sendmail Switch 2.2.3
Sendmail Inc Sendmail Switch 2.2.4
Sendmail Inc Sendmail Switch 2.2.5
Sendmail Inc Sendmail Switch 3.0
Sendmail Inc Sendmail Switch 3.0.1
Sendmail Inc Sendmail Switch 3.0.2
Sendmail Inc Sendmail Switch 3.0.3
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.2
SGI IRIX 6.5.3
SGI IRIX 6.5.4
SGI IRIX 6.5.5
SGI IRIX 6.5.6
SGI IRIX 6.5.7
SGI IRIX 6.5.8
SGI IRIX 6.5.9
SGI IRIX 6.5.10
SGI IRIX 6.5.11
SGI IRIX 6.5.12
SGI IRIX 6.5.13
SGI IRIX 6.5.14
SGI IRIX 6.5.15
SGI IRIX 6.5.16
SGI IRIX 6.5.17
SGI IRIX 6.5.18
SGI IRIX 6.5.19
Sun Solaris 2.4 _x86
Sun Solaris 2.4
Sun Solaris 2.5 _x86
Sun Solaris 2.5
Sun Solaris 2.5.1 _x86
Sun Solaris 2.5.1 _ppc
Sun Solaris 2.5.1
Sun Solaris 2.6 _x86
Sun Solaris 2.6
Sun Solaris 7.0 _x86
Sun Solaris 7.0
Sun Solaris 8.0 _x86
Sun Solaris 8.0
Sun Solaris 9.0 _x86 Update 2
Sun Solaris 9.0 _x86
Sun Solaris 9.0
详细描述
Sendmail存在一个远程缓冲区溢出漏洞。

此漏洞存在于prescan()过程中,此函数用于处理SMTP头中的EMAIL地址,由于在转换字符到整数时存在一个逻辑错误,导致能充分的检查email地址的长度。别创建地址的email消息可能触发一个栈溢出。

Sendmail 8.12.9已经修复了该漏洞。

解决方案
Compaq Tru64 4.0 g PK3 (BL17):

HP Patch t64v40gb17-c0029200-17810-es-20030403.tar
http://ftp.support.compaq.com/patches/public/unix/v4.0g/t64v40gb17-c0029200-17810-es-20030403.tar

Compaq Tru64 4.0 g:
Compaq Tru64 4.0 f PK7 (BL18):

HP Patch duv40fb18-c0093400-17811-es-20030403.tar
http://ftp.support.compaq.com/patches/public/unix/v4.0f/duv40fb18-c0093400-17811-es-20030403.tar

Compaq Tru64 4.0 f PK6 (BL17):
Compaq Tru64 4.0 f:
Compaq Tru64 4.0 d PK9 (BL17):
Compaq Tru64 4.0 d:
Compaq Tru64 4.0 b:
Compaq Tru64 5.0 f:
Compaq Tru64 5.0 a PK3 (BL17):
Compaq Tru64 5.0 a:
Compaq Tru64 5.0 PK4 (BL18):
Compaq Tru64 5.0 PK4 (BL17):
Compaq Tru64 5.0:
Compaq Tru64 5.1 b PK1 (BL1):

HP Patch t64v51bb1-c0008000-17812-es-20030403.tar
http://ftp.support.compaq.com/patches/public/unix/v5.1b/t64v51bb1-c0008000-17812-es-20030403.tar

Compaq Tru64 5.1 b:
Compaq Tru64 5.1 a PK3 (BL3):
Compaq Tru64 5.1 a PK2 (BL2):
Compaq Tru64 5.1 a PK1 (BL1):
Compaq Tru64 5.1 a:
Compaq Tru64 5.1 PK6 (BL20):

HP Patch t64v51b20-c0176700-17773-es-20030402.tar
http://ftp.support.compaq.com/patches/public/unix/v5.1/t64v51b20-c0176700-17773-es-20030402.tar

Compaq Tru64 5.1 PK5 (BL19):
Compaq Tru64 5.1 PK4 (BL18):
Compaq Tru64 5.1 PK3 (BL17):
Compaq Tru64 5.1:
HP NonStop-UX Whitney:
HP AltaVista Firewall Raptor EC:
HP NonStop-UX PUMA:
HP AltaVista Firewall AVFW98:
HP AlphaServer SC :
HP Tru64 5.1 a PK4 (BL21):

HP Patch t64v51ab21-c0112900-17770-es-20030402.tar
http://ftp.support.compaq.com/patches/public/unix/v5.1a/t64v51ab21-c0112900-17770-es-20030402.tar

HP Internet Express 5.4:
HP Internet Express 5.7:
HP Internet Express 5.8:
HP Internet Express 5.9:
HP Internet Express 6.0:
HP MPE/iX 6.0:
HP MPE/iX 6.5:
HP MPE/iX 7.0:

HP Upgrade SMLHD15A
http://itrc.hp.com
Requires installation of SMLGDT8A.

HP MPE/iX 7.5:

HP Upgrade SMLHD16A
http://itrc.hp.com

HP HP-UX 10.0 1:
HP HP-UX 10.0:
HP HP-UX 10.1:
HP HP-UX 10.8:
HP HP-UX 10.9:
HP HP-UX 10.10:
HP HP-UX 10.16:
HP HP-UX 10.20 SIS:
HP HP-UX 10.20 Series 800:
HP HP-UX 10.20 Series 700:
HP HP-UX 10.20:
HP HP-UX (VVOS) 10.24:
HP HP-UX 10.24:
HP HP-UX 10.26:
HP HP-UX 10.30:
HP HP-UX 10.34:
HP HP-UX 11.0 4:
HP HP-UX (VVOS) 11.0 4:
HP HP-UX 11.0:
HP HP-UX (VVOS) 11.0.4:
HP HP-UX 11.11:
HP HP-UX 11.20:
HP HP-UX 11.22:
NetBSD NetBSD 1.5:
NetBSD NetBSD 1.5.1:
NetBSD NetBSD 1.5.2:
NetBSD NetBSD 1.5.3:
NetBSD NetBSD 1.6:
Sendmail Consortium Sendmail 8.9 .0:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Patch prescan.tar.gz.uu
ftp://ftp.sendmail.org/pub/sendmail/prescan.tar.gz.uu
Source code patch for versions 8.9, 8.9.3. 8.11, 8.11.6, 8.12 and 8.12.8.

Sendmail Consortium Sendmail 8.9.1:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.9.2:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.9.3:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Patch prescan.tar.gz.uu
ftp://ftp.sendmail.org/pub/sendmail/prescan.tar.gz.uu
Source code patch for versions 8.9, 8.9.3. 8.11, 8.11.6, 8.12 and 8.12.8.

Sendmail Consortium Sendmail 8.10:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.10.1:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.10.2:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.11:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Patch prescan.tar.gz.uu
ftp://ftp.sendmail.org/pub/sendmail/prescan.tar.gz.uu
Source code patch for versions 8.9, 8.9.3. 8.11, 8.11.6, 8.12 and 8.12.8.

Sendmail Consortium Sendmail 8.11.1:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.11.2:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.11.3:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.11.4:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.11.5:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.11.6:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Patch prescan.tar.gz.uu
ftp://ftp.sendmail.org/pub/sendmail/prescan.tar.gz.uu
Source code patch for versions 8.9, 8.9.3. 8.11, 8.11.6, 8.12 and 8.12.8.

SCO Upgrade sendmail-8.11.6-14.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2003-016.0/RPMS/sendmail-8.11.6-14.i386.rpm

SCO Upgrade sendmail-8.11.6-14.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2003-016.0/RPMS/sendmail-8.11.6-14.i386.rpm

SCO Upgrade sendmail-8.11.6-14.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2003-016.0/RPMS/sendmail-8.11.6-14.i386.rpm

SCO Upgrade sendmail-8.11.6-14.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2003-016.0/RPMS/sendmail-8.11.6-14.i386.rpm

SCO Upgrade sendmail-cf-8.11.6-14.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2003-016.0/RPMS/sendmail-cf-8.11.6-14.i386.rpm

SCO Upgrade sendmail-cf-8.11.6-14.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2003-016.0/RPMS/sendmail-cf-8.11.6-14.i386.rpm

SCO Upgrade sendmail-cf-8.11.6-14.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2003-016.0/RPMS/sendmail-cf-8.11.6-14.i386.rpm

SCO Upgrade sendmail-cf-8.11.6-14.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2003-016.0/RPMS/sendmail-cf-8.11.6-14.i386.rpm

SCO Upgrade sendmail-doc-8.11.6-14.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2003-016.0/RPMS/sendmail-doc-8.11.6-14.i386.rpm

SCO Upgrade sendmail-doc-8.11.6-14.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2003-016.0/RPMS/sendmail-doc-8.11.6-14.i386.rpm

SCO Upgrade sendmail-doc-8.11.6-14.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2003-016.0/RPMS/sendmail-doc-8.11.6-14.i386.rpm

SCO Upgrade sendmail-doc-8.11.6-14.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2003-016.0/RPMS/sendmail-doc-8.11.6-14.i386.rpm

Conectiva Upgrade sendmail-8.11.6-1U60_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/sendmail-8.11.6-1U60_4cl.i386.rpm
Conectiva linux 6.0

Conectiva Upgrade sendmail-8.11.6-1U60_4cl.src.rpm
ftp://atualizacoes.conectiva.com.br/6.0/SRPMS/sendmail-8.11.6-1U60_4cl.src.rpm
Conectiva linux 6.0

Conectiva Upgrade sendmail-8.11.6-1U70_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/sendmail-8.11.6-1U70_4cl.i386.rpm
Conectiva linux 7.0

Conectiva Upgrade sendmail-8.11.6-1U70_4cl.src.rpm
ftp://atualizacoes.conectiva.com.br/7.0/SRPMS/sendmail-8.11.6-1U70_4cl.src.rpm
Conectiva linux 7.0

Conectiva Upgrade sendmail-8.11.6-2U80_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/sendmail-8.11.6-2U80_4cl.i386.rpm
Conectiva linux 8.0

Conectiva Upgrade sendmail-8.11.6-2U80_4cl.src.rpm
ftp://atualizacoes.conectiva.com.br/8/SRPMS/sendmail-8.11.6-2U80_4cl.src.rpm
Conectiva linux 8.0

Conectiva Upgrade sendmail-cf-8.11.6-1U60_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/sendmail-cf-8.11.6-1U60_4cl.i386.rpm
Conectiva linux 6.0

Conectiva Upgrade sendmail-cf-8.11.6-1U70_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/sendmail-cf-8.11.6-1U70_4cl.i386.rpm
Conectiva linux 7.0

Conectiva Upgrade sendmail-cf-8.11.6-2U80_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/sendmail-cf-8.11.6-2U80_4cl.i386.rpm
Conectiva linux 8.0

Conectiva Upgrade sendmail-doc-8.11.6-1U60_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/sendmail-doc-8.11.6-1U60_4cl.i386.rpm
Conectiva linux 6.0

Conectiva Upgrade sendmail-doc-8.11.6-1U70_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/sendmail-doc-8.11.6-1U70_4cl.i386.rpm
Conectiva linux 7.0

Conectiva Upgrade sendmail-doc-8.11.6-2U80_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/sendmail-doc-8.11.6-2U80_4cl.i386.rpm
Conectiva linux 8.0

Red Hat Upgrade sendmail-8.11.6-1.62.3.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/sendmail-8.11.6-1.62.3.i386.rpm

Red Hat Upgrade sendmail-8.11.6-25.70.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/sendmail-8.11.6-25.70.i386.rpm

Red Hat Upgrade sendmail-8.11.6-25.71.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/sendmail-8.11.6-25.71.i386.rpm

Red Hat Upgrade sendmail-8.11.6-25.72.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/sendmail-8.11.6-25.72.i386.rpm

Red Hat Upgrade sendmail-8.11.6-25.72.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/sendmail-8.11.6-25.72.ia64.rpm

Red Hat Upgrade sendmail-8.11.6-25.73.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/sendmail-8.11.6-25.73.i386.rpm

Red Hat Upgrade sendmail-cf-8.11.6-1.62.3.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/sendmail-cf-8.11.6-1.62.3.i386.rpm

Red Hat Upgrade sendmail-cf-8.11.6-25.70.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/sendmail-cf-8.11.6-25.70.i386.rpm

Red Hat Upgrade sendmail-cf-8.11.6-25.71.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/sendmail-cf-8.11.6-25.71.i386.rpm

Red Hat Upgrade sendmail-cf-8.11.6-25.72.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/sendmail-cf-8.11.6-25.72.i386.rpm

Red Hat Upgrade sendmail-cf-8.11.6-25.72.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/sendmail-cf-8.11.6-25.72.ia64.rpm

Red Hat Upgrade sendmail-cf-8.11.6-25.73.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/sendmail-cf-8.11.6-25.73.i386.rpm

Red Hat Upgrade sendmail-devel-8.11.6-25.70.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/sendmail-devel-8.11.6-25.70.i386.rpm

Red Hat Upgrade sendmail-devel-8.11.6-25.71.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/sendmail-devel-8.11.6-25.71.i386.rpm

Red Hat Upgrade sendmail-devel-8.11.6-25.72.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/sendmail-devel-8.11.6-25.72.i386.rpm

Red Hat Upgrade sendmail-devel-8.11.6-25.72.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/sendmail-devel-8.11.6-25.72.ia64.rpm

Red Hat Upgrade sendmail-devel-8.11.6-25.73.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/sendmail-devel-8.11.6-25.73.i386.rpm

Red Hat Upgrade sendmail-doc-8.11.6-1.62.3.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/sendmail-doc-8.11.6-1.62.3.i386.rpm

Red Hat Upgrade sendmail-doc-8.11.6-25.70.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/sendmail-doc-8.11.6-25.70.i386.rpm

Red Hat Upgrade sendmail-doc-8.11.6-25.71.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/sendmail-doc-8.11.6-25.71.i386.rpm

Red Hat Upgrade sendmail-doc-8.11.6-25.72.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/sendmail-doc-8.11.6-25.72.i386.rpm

Red Hat Upgrade sendmail-doc-8.11.6-25.72.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/sendmail-doc-8.11.6-25.72.ia64.rpm

Red Hat Upgrade sendmail-doc-8.11.6-25.73.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/sendmail-doc-8.11.6-25.73.i386.rpm

Sendmail Consortium Sendmail 8.12 beta7:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.12 beta5:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.12 beta16:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.12 beta12:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.12 beta10:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.12 .0:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Patch prescan.tar.gz.uu
ftp://ftp.sendmail.org/pub/sendmail/prescan.tar.gz.uu
Source code patch for versions 8.9, 8.9.3. 8.11, 8.11.6, 8.12 and 8.12.8.

Sendmail Consortium Sendmail 8.12.1:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.12.2:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

OpenBSD Patch 027_sendmail.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/027_sendmail.patch

Sendmail Consortium Sendmail 8.12.3:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.12.4:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

OpenBSD Patch 014_sendmail.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/014_sendmail.patch

Sendmail Consortium Sendmail 8.12.5:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

OpenBSD Patch 014_sendmail.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/014_sendmail.patch

Sendmail Consortium Sendmail 8.12.6:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

OpenBSD Patch 014_sendmail.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/014_sendmail.patch

Sendmail Consortium Sendmail 8.12.7:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Sendmail 8.12.8:

Sendmail Consortium Upgrade sendmail.8.12.9.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.9.tar.gz

Sendmail Consortium Patch prescan.tar.gz.uu
ftp://ftp.sendmail.org/pub/sendmail/prescan.tar.gz.uu
Source code patch for versions 8.9, 8.9.3. 8.11, 8.11.6, 8.12 and 8.12.8.

Red Hat Upgrade sendmail-8.12.8-5.80.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/sendmail-8.12.8-5.80.i386.rpm

Red Hat Upgrade sendmail-8.12.8-5.90.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/sendmail-8.12.8-5.90.i386.rpm

Red Hat Upgrade sendmail-cf-8.12.8-5.80.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/sendmail-cf-8.12.8-5.80.i386.rpm

Red Hat Upgrade sendmail-cf-8.12.8-5.90.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/sendmail-cf-8.12.8-5.90.i386.rpm

Red Hat Upgrade sendmail-devel-8.12.8-5.80.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/sendmail-devel-8.12.8-5.80.i386.rpm

Red Hat Upgrade sendmail-devel-8.12.8-5.90.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/sendmail-devel-8.12.8-5.90.i386.rpm

Red Hat Upgrade sendmail-doc-8.12.8-5.80.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/sendmail-doc-8.12.8-5.80.i386.rpm

Red Hat Upgrade sendmail-doc-8.12.8-5.90.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/sendmail-doc-8.12.8-5.90.i386.rpm

Sendmail Inc Sendmail Switch 2.1:
Sendmail Inc Sendmail Switch 2.1.1:
Sendmail Inc Sendmail Switch 2.1.2:
Sendmail Inc Sendmail Switch 2.1.3:
Sendmail Inc Sendmail Switch 2.1.4:
Sendmail Inc Sendmail Switch 2.1.5:
Sendmail Inc Sendmail Switch 2.2:
Sendmail Inc Sendmail Switch 2.2.1:
Sendmail Inc Sendmail Switch 2.2.2:
Sendmail Inc Sendmail Switch 2.2.3:
Sendmail Inc Sendmail Switch 2.2.4:
Sendmail Inc Sendmail Switch 2.2.5:
Sendmail Inc Sendmail for NT 2.6:
Sendmail Inc Sendmail for NT 2.6.1:
Sendmail Inc Sendmail for NT 2.6.2:
Sendmail Inc Sendmail for NT 3.0:
Sendmail Inc Sendmail Switch 3.0:
Sendmail Inc Sendmail for NT 3.0.1:
Sendmail Inc Sendmail Switch 3.0.1:
Sendmail Inc Sendmail for NT 3.0.2:
Sendmail Inc Sendmail Switch 3.0.2:
Sendmail Inc Sendmail Switch 3.0.3:
Sendmail Inc Sendmail for NT 3.0.3:
SGI IRIX 6.5:
SGI IRIX 6.5.1:
SGI IRIX 6.5.2:
SGI IRIX 6.5.3:
SGI IRIX 6.5.4:
SGI IRIX 6.5.5:
SGI IRIX 6.5.6:
SGI IRIX 6.5.7:
SGI IRIX 6.5.8:
SGI IRIX 6.5.9:
SGI IRIX 6.5.10:
SGI IRIX 6.5.11:
SGI IRIX 6.5.12:
SGI IRIX 6.5.13:
SGI IRIX 6.5.14:
SGI IRIX 6.5.15:

SGI Patch 5045
http://www.sgi.com/support/security/

SGI IRIX 6.5.16:

SGI Patch 5045
http://www.sgi.com/support/security/

SGI IRIX 6.5.17:

SGI Patch 5045
http://www.sgi.com/support/security/

SGI IRIX 6.5.18:

SGI Patch 5045
http://www.sgi.com/support/security/

SGI IRIX 6.5.19:

SGI Patch 5046
http://www.sgi.com/support/security/

Sun Solaris 2.4 _x86:
Sun Solaris 2.4:
Sun Solaris 2.5 _x86:
Sun Solaris 2.5:
Sun Solaris 2.5.1 _x86:
Sun Solaris 2.5.1 _ppc:
Sun Solaris 2.5.1:
Sun Solaris 2.6 _x86:

Sun Patch 105396-09
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=105396&rev=09

Sun Solaris 2.6:

Sun Patch 105395-09
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=105395&rev=09

Sun Solaris 7.0 _x86:

Sun Patch 107685-09
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=107685&rev=09

Sun Solaris 7.0:

Sun Patch 107684-09
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=107684&rev=09

Sun Solaris 8.0 _x86:

Sun Patch 110616-09
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=110616&rev=09

Sun Solaris 8.0:

Sun Patch 110615-09
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=110615&rev=09

Sun Solaris 9.0 _x86 Update 2:
Sun Solaris 9.0 _x86:

Sun Patch 114137-03
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=114137&rev=03

Sun Solaris 9.0:

Sun Patch 113575-04
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=113575&rev=04

相关信息
报告:Michal Zalewski
相关资料:http://marc.theaimsgroup.com/?l=bugtraq&m=104896621106790&w=2
          http://www.linux-mandrake.com/en/security/2003/2003-042.php
          https://www.redhat.com/support/errata/RHSA-2003-120.html
          http://sun