From owner-freebsd-security@FreeBSD.ORG Wed Sep 17 10:58:50 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9F40816A4B3; Wed, 17 Sep 2003 10:58:50 -0700 (PDT) Received: from smtp3.sentex.ca (smtp3.sentex.ca [64.7.153.18]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8D2C843FAF; Wed, 17 Sep 2003 10:58:49 -0700 (PDT) (envelope-from mike@sentex.net) Received: from lava.sentex.ca (pyroxene.sentex.ca [199.212.134.18]) by smtp3.sentex.ca (8.12.9/8.12.9) with ESMTP id h8HHwjDR018366; Wed, 17 Sep 2003 13:58:45 -0400 (EDT) (envelope-from mike@sentex.net) Received: from simian.sentex.net (simeon.sentex.ca [192.168.43.27]) by lava.sentex.ca (8.12.9/8.12.8) with ESMTP id h8HHwl5N083822; Wed, 17 Sep 2003 13:58:48 -0400 (EDT) (envelope-from mike@sentex.net) Message-Id: <6.0.0.22.0.20030917135827.0915f268@209.112.4.2> X-Sender: mdtpop@209.112.4.2 (Unverified) X-Mailer: QUALCOMM Windows Eudora Version 6.0.0.22 Date: Wed, 17 Sep 2003 14:01:29 -0400 To: Gregory Neil Shapiro From: Mike Tancsa In-Reply-To: <20030917175218.GX66258@horsey.gshapiro.net> References: <20030917162118.GB4838@madman.celabo.org> <6.0.0.22.0.20030917134441.08ac86a8@209.112.4.2> <20030917175218.GX66258@horsey.gshapiro.net> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii"; format=flowed X-Virus-Scanned: By Sentex Communications (lava/20020517) cc: freebsd-security@freebsd.org Subject: Re: Sendmail vulnerability X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 17 Sep 2003 17:58:50 -0000 If anything, just having the different version number on the banner makes it easier to track what has been updated as well as avoiding customers emailing us saying "Your version of sendmail is not safe" etc etc. Modifying the .mc is an option, but then its an extra step to unmodify it :-( Given that 4.9release has been pushed back a few weeks can the RE approve it ? Pretty please ? ;-) ---Mike At 01:52 PM 17/09/2003, Gregory Neil Shapiro wrote: >On Wed, Sep 17, 2003 at 01:46:14PM -0400, Mike Tancsa wrote: > > > > Looks like they have released http://www.sendmail.org/8.12.10.html > > > > Are their plans to import/mfc this into stable ? No doubt a busy day for > > the Sendmail folk as well :-( > >Import, yes. MFC is up to the RE's.