Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 14 Apr 1999 19:22:53 +0200
From:      Alain Thivillon <Alain.Thivillon@hsc.fr>
To:        "Andy V. Oleynik" <andyo@prime.net.ua>
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Re: Sendmail up to 8.9.2 vulnerability
Message-ID:  <19990414192253.D5661@yoko.hsc.fr>
In-Reply-To: <3714B71B.5420EB1F@prime.net.ua>; from Andy V. Oleynik on Wed, Apr 14, 1999 at 06:41:17PM %2B0300
References:  <3714B71B.5420EB1F@prime.net.ua>

next in thread | previous in thread | raw e-mail | index | archive | help
"Andy V. Oleynik" <andyo@prime.net.ua> écrivait (wrote) :

> What does he mean under "LA"?

Load Average. Sendmail eats all processing power during header parsing,
if you open 15 simultaneous sessions sending lot of headers, your load
average (ie number of runnable processes) will mount as high as 15, then
sendmail will refuse new connections (according to RefuseLa parameter,
by default 12).

> And may be some of U has appropriate patch for subj?

Install 8.9.3, who introduces 32K limit for total headers size and breaks
connection after that. Symptom is still here, but consequences are more
limited.

-- 
Alain Thivillon -+- Alain.Thivillon@hsc.fr -+- Hervé Schauer Consultants
Pgp Key ID: 0x57155CC9                                            AT1718 


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?19990414192253.D5661>