Just a heads-up everyone, the sendmail header parsing buffer
overflow announced this last Monday, as (among other things) CERT
CA-2003-07[1] is now being actively exploited on the internet.
We logged received msgs that triggered the truncator code this
morning at about 3 in the morning, US/Eastern; three different
attacks spread over two different MX hosts.
overflow announced this last Monday, as (among other things) CERT
CA-2003-07[1] is now being actively exploited on the internet.
We logged received msgs that triggered the truncator code this
morning at about 3 in the morning, US/Eastern; three different
attacks spread over two different MX hosts.
-Bennett
[1] <URL:http://www.cert.org/advisories/CA-2003-07.html>
[ reply ]