Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 20 Nov 1998 18:00:29 -0800
From:      Don Lewis <Don.Lewis@tsc.tdk.com>
To:        "Jordan K. Hubbard" <jkh@zippy.cdrom.com>, security@FreeBSD.ORG
Subject:   Re: "Todd C. Miller": sendmail changes in OpenBSD 2.4
Message-ID:  <199811210200.SAA28322@salsa.gv.tsc.tdk.com>
In-Reply-To: "Jordan K. Hubbard" <jkh@zippy.cdrom.com> ""Todd C. Miller": sendmail changes in OpenBSD 2.4" (Nov 15,  2:10pm)

next in thread | previous in thread | raw e-mail | index | archive | help

} To: announce@openbsd.org
} Subject: sendmail changes in OpenBSD 2.4
} Date: Sun, 15 Nov 1998 14:49:25 -0700
} From: "Todd C. Miller" <Todd.Miller@courtesan.com>
} Sender: owner-announce@openbsd.org
} 
} In 2.4, /usr/libexec/mail.local is no longer setuid, to prevent its
} abuse by users (trivial mail forgery, filling up /var/mail, etc).
} 
} If you are upgrading from a previous version of OpenBSD you will
} need to either regenerate your sendmail.cf with an OSTYPE of "openbsd"
} instead of "bsd4.4" or edit the sendmail.cf directly and in the
} line that begins with Mlocal, change the "rmn9" to "rmn9S".

This is not compatible with the RunAsUser sendmail option, which provides
some protection against sendmail exploits.

			---  Truck

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199811210200.SAA28322>