<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New sendmail issue? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939651#M930585</link>
    <description>To obscure the version / patch ID, modify this line in sendmail.cf:&lt;BR /&gt;&lt;BR /&gt;O SmtpGreetingMessage=$j Sendmail $v/$Z; $b&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 03 Apr 2003 21:00:49 GMT</pubDate>
    <dc:creator>Christopher Caldwell</dc:creator>
    <dc:date>2003-04-03T21:00:49Z</dc:date>
    <item>
      <title>New sendmail issue?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939644#M930576</link>
      <description>CERT Advisory CA-2003-12 Buffer Overflow in Sendmail addresses a new issue that is supossedly different from the one in CA-2003-07. &lt;BR /&gt;&lt;BR /&gt;The advisory did not have any comment from HP, and I was wondering if a new patch was needed for our HP-UX 11.00 systems.&lt;BR /&gt;&lt;BR /&gt;Thanks!</description>
      <pubDate>Mon, 31 Mar 2003 15:45:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939644#M930576</guid>
      <dc:creator>Gerald Miller_1</dc:creator>
      <dc:date>2003-03-31T15:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: New sendmail issue?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939645#M930577</link>
      <description>Here's a snipit from that CERT Advisory;&lt;BR /&gt;____________________________________________&lt;BR /&gt;Hewlett-Packard&lt;BR /&gt;SOURCE: Hewlett-Packard Company HP Services Software Security Response Team&lt;BR /&gt;&lt;BR /&gt;x-ref: SSRT3531&lt;BR /&gt;&lt;BR /&gt;At the time of writing this document, Hewlett Packard is currently investigating the potential impact to HP's released Operating System software products.&lt;BR /&gt;&lt;BR /&gt;As further information becomes available HP will provide notice of the availability of any necessary patches through standard security bulletin announcements and be available from your normal HP Services support channel. &lt;BR /&gt;____________________________________________&lt;BR /&gt;&lt;BR /&gt;I've looked at our security bulletins and have not seen one for this yet. I'm sure that if/when an issue is found that a security bulletin will be issued regarding any potential problem w/ a recommended action to resolve.&lt;BR /&gt;&lt;BR /&gt;To view security bulletins; start at the ITRC - &lt;A href="http://www.itrc.hp.com" target="_blank"&gt;http://www.itrc.hp.com&lt;/A&gt; -&amp;gt; click "maint and support" -&amp;gt; click "support info digests" at bottom of page, below notifications. Click "HP Security Bulletins Archive" at the bottom of page to view all sec bulletins.&lt;BR /&gt;&lt;BR /&gt;Hope this helps,&lt;BR /&gt;-denver</description>
      <pubDate>Mon, 31 Mar 2003 16:30:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939645#M930577</guid>
      <dc:creator>Denver Osborn</dc:creator>
      <dc:date>2003-03-31T16:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: New sendmail issue?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939646#M930578</link>
      <description>Denver,&lt;BR /&gt;Thanks for the help there... I didn't even bother to check the CERT site... I thought maybe they'd send me an email when they updated, but I guess not.&lt;BR /&gt;&lt;BR /&gt;Thanks for the information.</description>
      <pubDate>Mon, 31 Mar 2003 17:55:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939646#M930578</guid>
      <dc:creator>Gerald Miller_1</dc:creator>
      <dc:date>2003-03-31T17:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: New sendmail issue?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939647#M930579</link>
      <description>There will be a general release patch around 29 April that will address both Certs, CA-2003-12 and -07.  Again, these will be for 8.9.3 on 10.20 and 11.0 and 8.11.1 for 11.0 and 11i.&lt;BR /&gt;&lt;BR /&gt;I do not believe there will be any other release until then. &lt;BR /&gt;&lt;BR /&gt;Berlene</description>
      <pubDate>Mon, 31 Mar 2003 17:56:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939647#M930579</guid>
      <dc:creator>Berlene Herren</dc:creator>
      <dc:date>2003-03-31T17:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: New sendmail issue?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939648#M930581</link>
      <description>So those of us who went to the 8.11.x release sd-ux depots are left hanging?&lt;BR /&gt;&lt;BR /&gt;That hardly seems to be a balanced approach.&lt;BR /&gt;&lt;BR /&gt;Sendmail is becoming a very large security issue draining my resources from a complex server rollout project.&lt;BR /&gt;&lt;BR /&gt;My resources refers to my time.&lt;BR /&gt;&lt;BR /&gt;SEP&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Apr 2003 05:19:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939648#M930581</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-04-02T05:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: New sendmail issue?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939649#M930582</link>
      <description>Hi Gerald,&lt;BR /&gt;See my posting on same issue here:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0xc43eb941255cd71190080090279cd0f9,00.html" target="_blank"&gt;http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0xc43eb941255cd71190080090279cd0f9,00.html&lt;/A&gt;</description>
      <pubDate>Wed, 02 Apr 2003 08:52:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939649#M930582</guid>
      <dc:creator>Animesh Chakraborty</dc:creator>
      <dc:date>2003-04-02T08:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: New sendmail issue?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939650#M930584</link>
      <description>Hmmm,&lt;BR /&gt;&lt;BR /&gt;Comment 1) HP does seem to take its time patching what is in effect Open Source software. OTOH I built Sendmail 8.12.8 on an 11.00 box (selectively patched). My first issue was with PMTU. I was missing a Cumulative ARPA patch and mail to sites using CISCO PIX firewalls and the 'Mail Guard' feature turned on  stalled in the queue. Once that was fixed after running for 36 hours I started seeing kernel memory leaks.&lt;BR /&gt;&lt;BR /&gt;I suspect my GNU toolchain..but haven't verified that as the problem yet.&lt;BR /&gt;&lt;BR /&gt; I fell back to HP 8.11.1 + JagGae58098 and that worked fine.&lt;BR /&gt;&lt;BR /&gt;Comment 2) Don't make it easy to find hackable targets!!!&lt;BR /&gt;&lt;BR /&gt;WHY does sendmail (from HP or sendmail.org) have to identify its version in the smtp greeting  , the help message, and any message headers. HP's case is even worse since the most recently applied patch is also identified.&lt;BR /&gt;&lt;BR /&gt;An administrator can modify the greeting message, and can modify the headers, and can remove the version from the help file. BUT if you remove the whole help file sendmail will generate a HARD CODED message telling you help is not available - with it's version embedded in the message.&lt;BR /&gt;&lt;BR /&gt;Berlen H. please pass these last comments along to see if the next patch can obscure version/patch info from the outside world.&lt;BR /&gt;&lt;BR /&gt;TIA,&lt;BR /&gt;&lt;BR /&gt;Scott.</description>
      <pubDate>Wed, 02 Apr 2003 20:30:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939650#M930584</guid>
      <dc:creator>Scott Donaldson</dc:creator>
      <dc:date>2003-04-02T20:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: New sendmail issue?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939651#M930585</link>
      <description>To obscure the version / patch ID, modify this line in sendmail.cf:&lt;BR /&gt;&lt;BR /&gt;O SmtpGreetingMessage=$j Sendmail $v/$Z; $b&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 03 Apr 2003 21:00:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939651#M930585</guid>
      <dc:creator>Christopher Caldwell</dc:creator>
      <dc:date>2003-04-03T21:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: New sendmail issue?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939652#M930587</link>
      <description>Yup --&lt;BR /&gt;&lt;BR /&gt;see&lt;BR /&gt;&lt;BR /&gt;SECURITY BULLETIN: HPSBUX0304-253&lt;BR /&gt;&lt;BR /&gt;You need           sendmail.811.11.11.r2.&lt;BR /&gt;</description>
      <pubDate>Fri, 04 Apr 2003 13:29:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/new-sendmail-issue/m-p/2939652#M930587</guid>
      <dc:creator>Christopher Caldwell</dc:creator>
      <dc:date>2003-04-04T13:29:35Z</dc:date>
    </item>
  </channel>
</rss>

