[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-security] poprelay: serious security bug



On 04 Jul 2001 21:49:16 +0100, Jonathan Michaelson wrote:
> 
> For those running the poprelayd POP-before-relay daemon (including the
> "official" Cobalt release), you should note that a serious bug + exploit has
> been posted to BugTraq with specific reference to the Cobalt RaQ3 (but will
> certainly affect _all_ the RaQ servers running poprelayd):
> 
> http://www.securityfocus.com/templates/archive.pike?mid=194906&threads=0&lis
> t=1&end=2001-07-07&start=2001-07-01&fromthread=0&
> 
> The bug + exploit allows anyone to relay mail through the server. We can
> only hope that Cobalt comes out with a remedy for this problem *very*
> quickly.

Ugh. I just got this email, and I am working on a patch right now.

We recieved no notification of this exploit before it was posted
to Bugtraq.  http://www.wiretrip.net/rfp/policy.html describes the
notification policy, which was not followed in this case.

I apologize for this lack communication and the ability to provide
you with a patch in a timely fashion.  I will try to get a patch
available as soon as possible.

Jeff

-- 
Jeff Lovell
Sun Microsystems Inc.