Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2003:028: sendmail Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the sendmail package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2003:028 (sendmail).
A vulnerability was discovered in sendmail by Mark Dowd of ISS X-Force that
involves mail header manipulation that can result in a remote user gaining root
access to the system running the vulnerable sendmail.
Patches supplied by the sendmail development team have been applied to correct
this issue. MandrakeSoft encourages all users who have chosen to use sendmail
(as opposed to the default MTA, postfix) to upgrade to this version of sendmail
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:028
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.