Re: Vixie Cron version 3.0pl1 vulnerable to root exploit

1999-09-07 Thread Martin Schulze
Valentin Nechayev wrote: Quite more simple and correct variant is to append "--" to mailargs: -#define MAILARGS "%s -FCronDaemon -odi -oem -or0s %s" /*-*/ +#define MAILARGS "%s -FCronDaemon -odi -oem -- %s" /*-*/ After it, it's possible to use real local parts

Re: Vixie Cron version 3.0pl1 vulnerable to root exploit

1999-09-03 Thread Valentin Nechayev
Martin Schulze [EMAIL PROTECTED] wrote: Red Hat has recently released a Security Advisory (RHSA-1999:030-01) covering a reverse denial of service bug in the vixie cron package. As user you could restart sendmail even if the host should not receive mail through the SMTP port. Further

Vixie Cron version 3.0pl1 vulnerable to root exploit

1999-08-30 Thread Martin Schulze
Red Hat has recently released a Security Advisory (RHSA-1999:030-01) covering a reverse denial of service bug in the vixie cron package. As user you could restart sendmail even if the host should not receive mail through the SMTP port. Further investigation discovered that it was even worse.