OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: SA-03:04.sendmail Bin Update

From: Jacques A. Vidrine (nectarFreeBSD.org)
Date: Tue Mar 04 2003 - 09:06:29 CST


On Mon, Mar 03, 2003 at 04:59:02PM -0800, Chris McCluskey wrote:
> Just want to verify. The binary Sendmail update is for 8.12.6 not the
> newly released 8.12.8 correct? Just got thrown off when after running
> install the logged version of Sendmail was the same. If this is
> correct, is there a way to verify that the currently running version
> is the patched version?

The sendmail binaries from SA-03:04 (on ftp.freebsd.org) are the same
binaries you would get if you CVSup'd on the security branch and rebuilt.
So that's correct -- the version number does not change.

The patch added a new log message which you can check for. Do
`strings /path/to/sendmail | grep Dropped'.

  % strings ./sendmail-4.6-i386-crypto.bin| grep Dropped
  Dropped invalid comments from header address

Cheers,
--
Jacques A. Vidrine <nectarcelabo.org> http://www.celabo.org/
NTT/Verio SME . FreeBSD UNIX . Heimdal Kerberos
jvidrineverio.net . nectarFreeBSD.org . nectarkth.se

To Unsubscribe: send mail to majordomoFreeBSD.org
with "unsubscribe freebsd-security" in the body of the message