[RHSA-2003:073-06] Updated sendmail packages fix critical sec urity issues

Spicer, Kevin Kevin.Spicer at BMRB.CO.UK
Mon Mar 3 22:08:57 GMT 2003


Funnily enough I just upgraded my home box and didn't have a problem - reading the post install script it looks like the mandrake rpm runs a 'service sendmail restart' if it fins /var/lock/subsys/sendmail I guess I must have killed sendmail at some point when I built the box.  chkconfig didn't turn anything on in either case (just a random sendmail process got kicked off).

Julian, there seem to be quite regular messages here from people who either didn't turn sendmail off with chkconfig, or who have random other sendmail processes running, (or who have packaging systems making random changes!) perhaps check_MailScanner should check for this?

> -----Original Message-----
> From: Spicer, Kevin 
> Sent: 03 March 2003 20:50
> To: MAILSCANNER at JISCMAIL.AC.UK
> Subject: Re: [RHSA-2003:073-06] Updated sendmail packages fix critical
> sec urity issues
> 
> 
> Thanks for that!  One little gotcha to look out for... I just 
> upgraded the rpms on my Mandrake box and the postinstall 
> script kicked off a new sendmail process, bypassing 
> MailScanner (Whoops!).  Dunno if this happens with other 
> packages but its worth checking!
> 
> > -----Original Message-----
> > From: Richard, Matt [mailto:matthew.richard at COCC.COM] 
> > Sent: Monday, March 03, 2003 9:49 AM
> > To: MAILSCANNER at JISCMAIL.AC.UK
> > Subject: FW: [RHSA-2003:073-06] Updated sendmail packages 
> fix critical
> > sec urity issues
> > 
> > 
> > For those who have not already seen the advisory.  It appears 
> > to effect
> > sendmail on many different platforms.
> > 
> > 
> 
> 
> 
> BMRB International 
> http://www.bmrb.co.uk
> +44 (0)20 8566 5000
> _________________________________________________________________
> This message (and any attachment) is intended only for the 
> recipient and may contain confidential and/or privileged 
> material.  If you have received this in error, please contact the 
> sender and delete this message immediately.  Disclosure, copying 
> or other action taken in respect of this email or in 
> reliance on it is prohibited.  BMRB International Limited 
> accepts no liability in relation to any personal emails, or 
> content of any email which does not directly relate to our 
> business.
> 



BMRB International 
http://www.bmrb.co.uk
+44 (0)20 8566 5000
_________________________________________________________________
This message (and any attachment) is intended only for the 
recipient and may contain confidential and/or privileged 
material.  If you have received this in error, please contact the 
sender and delete this message immediately.  Disclosure, copying 
or other action taken in respect of this email or in 
reliance on it is prohibited.  BMRB International Limited 
accepts no liability in relation to any personal emails, or 
content of any email which does not directly relate to our 
business.




More information about the MailScanner mailing list