[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-security] poprelay: serious security bug
- Subject: Re: [cobalt-security] poprelay: serious security bug
- From: Jeff Lovell <jlovell@xxxxxxx>
- Date: 09 Jul 2001 09:34:34 -0700
- List-id: Mailing list for users to address network security on Cobalt products. <cobalt-security.list.cobalt.com>
On 04 Jul 2001 21:49:16 +0100, Jonathan Michaelson wrote:
>
> For those running the poprelayd POP-before-relay daemon (including the
> "official" Cobalt release), you should note that a serious bug + exploit has
> been posted to BugTraq with specific reference to the Cobalt RaQ3 (but will
> certainly affect _all_ the RaQ servers running poprelayd):
>
> http://www.securityfocus.com/templates/archive.pike?mid=194906&threads=0&lis
> t=1&end=2001-07-07&start=2001-07-01&fromthread=0&
>
> The bug + exploit allows anyone to relay mail through the server. We can
> only hope that Cobalt comes out with a remedy for this problem *very*
> quickly.
Ugh. I just got this email, and I am working on a patch right now.
We recieved no notification of this exploit before it was posted
to Bugtraq. http://www.wiretrip.net/rfp/policy.html describes the
notification policy, which was not followed in this case.
I apologize for this lack communication and the ability to provide
you with a patch in a timely fashion. I will try to get a patch
available as soon as possible.
Jeff
--
Jeff Lovell
Sun Microsystems Inc.