Another Sendmail security hole

, posted: 1-Apr-2006 12:55

Yesterday, a security announcement from OpenBSD appeared in my inbox:

A race condition exists in sendmail's handling of asynchronous signals.
A remote attacker may be able to execute arbitrary source code with the
privileges of the user running sendmail, typically root.

Ugh. Luckily, I don't expose Sendmail to the Internet. Exim is my favourite Mail Transfer Agent, and has been for a long while now, and I can thoroughly recommend it over Sendmail. Postfix is also good.

I see that FreeBSD had a Security Advisory out on the Sendmail race condition by March 22 already.
Wonder why OpenBSD, which is so security-oriented, took so long to send out theirs? Also, does this count as the second remotely exploitable security hole in OpenBSD's default installation...?

Either way, if you have Sendmail running anywhere, it's time to patch. Or, you could just install Exim instead. :)

