=====================================================================
                                    CERT-Renater

                         Note d'Information No. 2006/VULN127
_____________________________________________________________________

DATE                      : 31/03/2006

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : OpenBSD running Sendmail.

======================================================================

A race condition exists in sendmail's handling of asynchronous signals.
A remote attacker may be able to execute arbitrary source code with the
privileges of the user running sendmail, typically root.

The fixes have been applied to the 3.7-stable, 3.8-stable and 3.9-stable
branches, and are also available as patches.  3.9-current has been
updated to the new sendmail version which has this addressed as well.

Patches for the respective releases:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/001_sendmail.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/006_sendmail.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/012_sendmail.patch

======================================================================

           =========================================================
           Les serveurs de référence du CERT-Renater
           http://www.urec.fr/securite
           http://www.cru.fr/securite
           http://www.renater.fr
           =========================================================
           + CERT-RENATER          | tel : 01-53-94-20-44          +
           + 151 bd de l'Hopital   | fax : 01-53-94-20-41          +
           + 75013 Paris           | email: certsvp@renater.fr     +
           =========================================================


