Package: sendmail
Version: 8.13.4-3
Followup-For: Bug #358440

tags 358440 security
thanks

Cert also lists this bug:
http://www.us-cert.gov/cas/techalerts/TA06-081A.html


-- Package-specific info:
Ouput of /usr/share/bug/sendmail/script:

ls -alR /etc/mail:
/etc/mail:
total 251
-rw-r--r--    1 root  smmsp   128 Oct 31  2002 --help
drwxr-sr-x    7 smmta smmsp  1024 Feb 23 14:31 .
drwxr-xr-x  126 root  root   6144 Mar 22 05:39 ..
-rwxr-xr--    1 root  smmsp  9050 Aug 14  2005 Makefile
-rw-r--r--    1 root  mail   6898 Dec 31  2001 Makefile.bad
-rw-r--r--    1 root  mail   6897 Dec 31  2001 Makefile.fix
-rw-r--r--    1 root  root    281 Jun  3  2005 address.resolve
-rw-r--r--    1 root  smmsp  5406 Feb 23 14:31 aliases
-rw-r-----    1 smmta smmsp 12288 Feb 23 14:31 aliases.db
-rw-r--r--    1 root  root   3201 Aug 14  2005 databases
-rw-r--r--    1 mail  mail   5588 Jun  3  2005 helpfile
-rw-r--r--    1 root  smmsp   175 Oct 16  2003 local-host-names
drwxr-sr-x    2 smmta smmsp  1024 Aug 14  2005 m4
drwxr-xr-x    2 root  root   1024 Aug 14  2005 peers
-rw-r--r--    1 root  smmsp    22 Oct 28  2002 relay-domains
drwxr-xr-x    2 root  smmsp  1024 Jun  3  2005 sasl
-rw-r--r--    1 root  smmsp 47237 Sep 27 20:19 sendmail.cf
-rw-r--r--    1 root  smmsp   300 Sep 27 20:19 sendmail.cf.errors
-rw-r--r--    1 root  root  11883 Aug 14  2005 sendmail.conf
-rw-r--r--    1 root  smmsp  3795 Aug 14  2005 sendmail.mc
-rw-r--r--    1 root  smmsp  3198 Jul 14  2002 sendmail.mc.noosiru
-rw-r--r--    1 root  smmsp  3298 Jul 14  2002 sendmail.mc.ok
-rw-r--r--    1 root  root    149 Oct 25  1999 service.switch
-rw-r--r--    1 root  root    180 Oct 25  1999 service.switch-nodns
drwxr-sr-x    2 smmta smmsp  1024 Aug 18  2005 smrsh
lrwxrwxrwx    1 root  root     15 Aug 14  2005 spamassassin -> ../spamassassin
-rw-r--r--    1 root  smmsp 43604 Aug 14  2005 submit.cf
-rw-r--r--    1 root  smmsp  2014 Aug 14  2005 submit.mc
drwxr-xr-x    2 smmta smmsp  1024 Aug 14  2005 tls
-rw-r--r--    1 root  smmsp     0 Aug 14  2005 trusted-users

/etc/mail/m4:
total 2
drwxr-sr-x  2 smmta smmsp 1024 Aug 14  2005 .
drwxr-sr-x  7 smmta smmsp 1024 Feb 23 14:31 ..
-rw-r-----  1 root  smmsp    0 Aug 14  2005 dialup.m4
-rw-r-----  1 root  smmsp    0 Aug 14  2005 provider.m4

/etc/mail/peers:
total 3
drwxr-xr-x  2 root  root  1024 Aug 14  2005 .
drwxr-sr-x  7 smmta smmsp 1024 Feb 23 14:31 ..
-rw-r--r--  1 root  root   328 Jul 17  2001 provider

/etc/mail/sasl:
total 2
drwxr-xr-x  2 root  smmsp 1024 Jun  3  2005 .
drwxr-sr-x  7 smmta smmsp 1024 Feb 23 14:31 ..

/etc/mail/smrsh:
total 3
drwxr-sr-x  2 smmta smmsp 1024 Aug 18  2005 .
drwxr-sr-x  7 smmta smmsp 1024 Feb 23 14:31 ..
-rwxr-xr-x  1 root  smmsp   82 Aug 18  2005 ecartis
lrwxrwxrwx  1 root  smmsp   26 Aug 14  2005 mail.local -> 
/usr/lib/sm.bin/mail.local
lrwxrwxrwx  1 root  smmsp   25 Aug 15  2005 mail2news -> 
/usr/local/sbin/mail2news
lrwxrwxrwx  1 root  smmsp   17 Aug 14  2005 procmail -> /usr/bin/procmail
lrwxrwxrwx  1 root  smmsp   17 Aug 14  2005 vacation -> /usr/bin/vacation

/etc/mail/tls:
total 19
drwxr-xr-x  2 smmta smmsp 1024 Aug 14  2005 .
drwxr-sr-x  7 smmta smmsp 1024 Feb 23 14:31 ..
-rw-r--r--  1 root  root     7 Aug 14  2005 no_prompt
-rw-------  1 root  root  1191 Aug 14  2005 sendmail-client.cfg
-rw-r--r--  1 root  smmsp 1172 Aug 14  2005 sendmail-client.crt
-rw-------  1 root  root   989 Aug 14  2005 sendmail-client.csr
-rw-r-----  1 root  smmsp 1679 Aug 14  2005 sendmail-common.key
-rw-------  1 root  root     0 Aug 14  2005 sendmail-common.prm
-rw-------  1 root  root  1191 Aug 14  2005 sendmail-server.cfg
-rw-r--r--  1 root  smmsp 1172 Aug 14  2005 sendmail-server.crt
-rw-------  1 root  root   989 Aug 14  2005 sendmail-server.csr
-rwxr--r--  1 root  root  3137 Aug 14  2005 starttls.m4

sendmail.conf:
DAEMON_NETMODE="Static";
DAEMON_NETIF="lo";
DAEMON_MODE="Daemon";
DAEMON_PARMS="";
DAEMON_HOSTSTATS="Yes";
DAEMON_MAILSTATS="No";
QUEUE_MODE="${DAEMON_MODE}";
QUEUE_INTERVAL="10m";
QUEUE_PARMS="";
MSP_MODE="Cron";
MSP_INTERVAL="20m";
MSP_PARMS="";
MSP_MAILSTATS="${DAEMON_MAILSTATS}";
MISC_PARMS="";
CRON_MAILTO="root";
CRON_PARMS="";
LOG_CMDS="No";
HANDS_OFF="No";
AGE_DATA="";
DAEMON_RUNASUSER="No";
DAEMON_STATS="${DAEMON_MAILSTATS}";
MSP_STATS="${MSP_MAILSTATS}";


sendmail.mc:
divert(-1)
divert(0)
define(`_USE_ETC_MAIL_')dnl
define(`confPRIVACY_FLAGS', 
`needmailhelo,authwarnings,novrfy,noexpn,norecipts,nobodyreturn')dnl
define(`confMAX_MESSAGE_SIZE', `1400000')dnl
include(`/usr/share/sendmail/cf/m4/cf.m4')dnl
VERSIONID(`@(#)sendmail.mc      8.9.3-21 (Debian) 20000309')
OSTYPE(`debian')dnl
DOMAIN(`debian-mta')dnl
LOCAL_CONFIG
FEATURE(masquerade_envelope)dnl
FEATURE(always_add_domain)dnl
Cwblars.org
FEATURE(`relay_entire_domain')dnl
FEATURE(use_cw_file)dnl
FEATURE(use_ct_file)dnl
FEATURE(`nouucp', `reject')dnl
FEATURE(`smrsh')dnl
include(`/etc/mail/tls/starttls.m4')dnl
FEATURE(`dnsbl',`list.dsbl.org',`"mail from open proxies and relays refused, 
see http://www.dsbl.org";')dnl
FEATURE(`dnsbl',`sbl-xbl.spamhaus.org',`"mail from spammers refused, see 
http://www.spamhaus.org";')
FEATURE(`dnsbl',`block.blars.org',`"mail from spamming sites refused, see 
http://www.blars.org/errors/block.html";')dnl
define(`confME_TOO', True)dnl
MAILER_DEFINITIONS
MAILER(local)dnl
MAILER(smtp)dnl
LOCAL_CONFIG
MASQUERADE_AS(blars.org)dnl
LOCAL_RULESETS
HContent-Type:  $>CheckContentType
HReturn-Receipt-To:     $>ReturnReciept
HX-MailScanner: $>MailScanner
SCheckContentType
Rtext/html$*                    $#error $: 553 html mail refused
Rapplication/pgp$*              $@ OK
Rapplication$*                  $#error $: 553 non-text email refused
Rimage$*                        $#error $: 553 non-text email refused
R$*charset=koi$*                $#error $: 553 non-english email refused
R$*                             $@ OK
SReturnReciept
R$*                             $#error $: 553 Mail requesting return reciept 
rejected
SMailScanner

submit.mc...
divert(-1)dnl
divert(0)dnl
define(`_USE_ETC_MAIL_')dnl
include(`/usr/share/sendmail/cf/m4/cf.m4')dnl
VERSIONID(`$Id: submit.mc, v 8.12.0.Beta19 2001/04/23 12:00:00 cowboy Exp $')
OSTYPE(`debian')dnl
DOMAIN(`debian-msp')dnl
include(`/etc/mail/tls/starttls.m4')dnl
FEATURE(`msp')dnl


-- System Information:
Debian Release: 3.1
Architecture: i386 (i686)
Kernel: Linux 2.4.27-2-686
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)

Versions of packages sendmail depends on:
ii  rmail                         8.13.4-3   MTA->UUCP remote mail handler
ii  sendmail-base                 8.13.4-3   powerful, efficient, and scalable 
ii  sendmail-bin                  8.13.4-3   powerful, efficient, and scalable 
ii  sendmail-cf                   8.13.4-3   powerful, efficient, and scalable 
ii  sensible-mda                  8.13.4-3   Mail Delivery Agent wrapper

Versions of packages sensible-mda depends on:
ii  libc6                       2.3.2.ds1-22 GNU C Library: Shared libraries an
ii  procmail                    3.22-11      Versatile e-mail processor
ii  sendmail-bin [mail-transpor 8.13.4-3     powerful, efficient, and scalable 

Versions of packages rmail depends on:
ii  libc6                       2.3.2.ds1-22 GNU C Library: Shared libraries an
ii  libldap2                    2.1.30-8     OpenLDAP libraries
ii  sendmail-bin [mail-transpor 8.13.4-3     powerful, efficient, and scalable 

Versions of packages libmilter0 depends on:
ii  libc6                       2.3.2.ds1-22 GNU C Library: Shared libraries an

-- no debconf information

-- 
Blars Blarson                   [EMAIL PROTECTED]
                                http://www.blars.org/blars.html
With Microsoft, failure is not an option.  It is a standard feature.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to