ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Companies urged to patch Sendmail

Published: 04 Mar 2003 08:53 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A critical vulnerability in Sendmail, the Internet's most popular mail-server application, had security experts and software companies moving quickly on Monday to convince customers to apply a patch.

The flaw allows an attacker to send a specially formatted email that could take control of a mail server running Sendmail and execute a malicious program. At present, no attack tool that could exploit the vulnerability is known to exist, said Greg Olson, chairman and co-founder of Sendmail, the company that has created a commercial version of the software.

"You have to understand that this is a very arcane security issue," he said. "It has been present in Sendmail code for 15 years and that code has been through multiple inspections."

The flaw -- ironically in a Sendmail security function -- occurs when the mail program parses an overlong header. The vulnerability was first found in December by security software firm Internet Security Systems. The company notified Sendmail and the National Infrastructure Protection Center, a joint computer crime and security task force, on 13 January.

"This vulnerability is especially dangerous because the exploit can be delivered within an email message and the attacker doesn't need any specific knowledge of the target to launch a successful attack," stated an ISS advisory released on Monday.

Because the vulnerability is contained in an email message, it will bypass firewalls and many intrusion detection systems, said Dan Ingsvaldson, team leader for ISS's vulnerability research group. Moreover, mail servers -- also called mail transport agents (MTAs) -- that aren't vulnerable will still forward the flaw-exploiting email message onto its destination.

"The only dependency is that the domain needs to accept email," Ingevaldson said.

The flaw is unrelated to a November break-in at the Sendmail Consortium's Web site.

Several companies, including Red Hat, IBM, SGI, Sun and Hewlett-Packard, released patches on Monday. The Sendmail Consortium, the group responsible for development of the open-source Sendmail code, released Sendmail 8.12.8, an updated program that fixes the flaw.

"The key here is to get the word out and get it fixed before hackers get an exploit," said Sendmail's Olson. "You need to contact a lot of people and make sure they understand this is important and apply the patch."


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
46 out of 114 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Websphere Message Broker Consultant

My client, a financial insitution requires a Websphere Message Broker consultant to join their programme. Ideal candidates will have excellent ...

Transport/Despatch Manager - East Midlands - Circa 26,000

Huxley Associates are proud to be representing one of the world global leaders within the point of purchase market in their search for a Transport/ ...

UNIX, C / C++ Experienced Developer C / C++, UNIX - London Ref: 21026

Pension Life Assurance x5life Vision Care Long term disability Transport Benefits Parenting Resources EAP Wellbeing Onsite Nurse Bloomberg University ...

Discussions

Moley Moley

welcome to www.007trader.com

Saturday 17 May 2008, 11:37 PM

3 posts
Tallin Tallin

welcome to www.007trader.com

Saturday 17 May 2008, 11:11 PM

3 posts
Moley Moley

Pride

Saturday 17 May 2008, 10:10 PM

6 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal