[Bug 58817] Please sync sendmail (universe) from unstable (main)

Martin Pitt martin.pitt at ubuntu.com
Mon Sep 4 08:51:05 BST 2006


Public bug reported:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 affects distros/ubuntu/sendmail
 status confirmed
 subscribe ubuntu-archive

Please sync sendmail (universe) from Debian unstable (main).

Changelog since current edgy version 8.13.7-2:

sendmail (8.13.8-2) unstable; urgency=low

   * /var/lib/sendmail must not be group-writable, but
     /var/lib/sendmail/dead.letter must be
     closes: #385440, #385502
   * apply patch to stop assertion with -bs

 -- Richard A Nelson (Rick) <cowboy at debian.org>  Fri, 01 Sep 2006
04:57:00 -0000

sendmail (8.13.8-1) unstable; urgency=high

   * CVE-2006-4434: sendmail 8.13.8 fixes remote DoS vulnerability
     use-after-free vulnerability in Sendmail before 8.13.8
     closes: #385054

   * I hadn't released this earlier because I had the 8.13.7 errata
     patches in 8.13.7-2, so it didn't look like a big deal.

 -- Richard A Nelson (Rick) <cowboy at debian.org>  Tue, 29 Aug 2006
14:00:00 -0000

sendmail (8.13.8-0) private; urgency=low

   * New upstream - not much new (already had the errata in 8.13.7-2)
   * Refit patches
   * /var/lib/sendmail needs to be writable by smmsp for dead.letter

 -- Richard A Nelson (Rick) <cowboy at debian.org>  Wed, 09 Aug 2006
16:50:00 -0000


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)

iD8DBQFE+9sRDecnbV4Fd/IRAsNgAJ9k9iRXUuJUg7lTE62cf3RIzLV3PwCg2mpP
LkLTIHSwBwkdPTjenFZirDE=
=m7gd
-----END PGP SIGNATURE-----

** Affects: sendmail (Ubuntu)
     Importance: Untriaged
         Status: Confirmed

-- 
Please sync sendmail (universe) from unstable (main)
https://launchpad.net/bugs/58817



More information about the ubuntu-archive mailing list