From owner-freebsd-questions@FreeBSD.ORG Wed Jun 16 18:58:22 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 0A28916A4CE for ; Wed, 16 Jun 2004 18:58:22 +0000 (GMT) Received: from smtp03.mrf.mail.rcn.net (smtp03.mrf.mail.rcn.net [207.172.4.62]) by mx1.FreeBSD.org (Postfix) with ESMTP id E213343D39 for ; Wed, 16 Jun 2004 18:58:21 +0000 (GMT) (envelope-from roberthuff@rcn.com) Received: from 209-6-197-67.c3-0.smr-ubr1.sbo-smr.ma.cable.rcn.com ([209.6.197.67] helo=jerusalem.litteratus.org.litteratus.org) by smtp03.mrf.mail.rcn.net with esmtp (Exim 3.35 #7) id 1Bafbm-00021K-00 for freebsd-questions@freebsd.org; Wed, 16 Jun 2004 14:58:07 -0400 From: Robert Huff MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Message-ID: <16592.38955.399680.399710@jerusalem.litteratus.org> Date: Wed, 16 Jun 2004 14:57:47 -0400 To: freebsd-questions@freebsd.org In-Reply-To: <40D081D1.1060606@mac.com> References: <40D023A1.8090009@cs.uiowa.edu> <20040616140305.GD32001@millerlite.local.mark-and-erika.com> <20040616145305.GB15913@ei.bzerk.org> <40D081D1.1060606@mac.com> X-Mailer: VM 7.17 under 21.5 (beta16) "celeriac" XEmacs Lucid Subject: Re: Mail X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 16 Jun 2004 18:58:22 -0000 Chuck Swiger writes: > There have been around 70 security issues mentioned since the > beginning of sendmail-8 circa 1993, or about six per year. > Recently, things have gotten better, but a dispassionate > evaluation of the security history of sendmail does not inspire > any great confidence that one can set up sendmail, leave it > unpatched, and expect the software to still be free of known > remotely-exploitable security problems two years later. Would you care to nominate an inherently network-accessible program with such a track record? For example: 5.2.1 was released in late February; there are currently 12 security advisories*, of which I would consider at least 5 to be part of the core system. (As opposed to things in the base system, like BIND.) Robert Huff * - see "http://www.freebsd.org/releases/5.2.1R/relnotes-i386.html#SECURITY"