OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 3rd quarter (Jul-Sep) 1997: sendmail -C: Known? Patches? (AIX 4.1.5)

sendmail -C: Known? Patches? (AIX 4.1.5)

DI. Dr. Klaus Kusche (Klaus.KuscheOOE.GV.AT)
Wed, 6 Aug 1997 08:07:36 PDT

On several not-so-official WWW pages, I found a hint that

/usr/lib/sendmail -C <any-file-you-want-to-read>

produces "interesting" output.

I tried that on our AIX 4.1.5 (as an ordinary user!) with
"/etc/security/passwd", and it indeed displayed all the
shadow passwords.

I checked IBM's and CERT's archives about it and found nothing.

Questions:
1.) Is the problem known?
2.) Does IBM have a fix for it?
3.) Is it fixed in the latest (non-IBM) sendmail releases?

DI. Dr. Klaus Kusche
Oberoesterreichische Landesregierung / Government of Upper Austria
Rechenzentrum / Computing Centre
Smail: Kaerntnerstrasse 16, A-4020 Linz, Austria (Europe)
Phone: +43 732 7720 - 3394   Fax: +43 732 7720 - 3198
Email: Klaus.Kuscheooe.gv.at