Operating System - HP-UX
1753441 Members
4582 Online
108794 Solutions
New Discussion юеВ

Re: Sendmail CVE-2009-4565 CERT

 
SOLVED
Go to solution
DShinn
Frequent Advisor

Sendmail CVE-2009-4565 CERT

Does anyone know what the plan is to address this CERT?

Thank-you,

Dorothy
4 REPLIES 4
Steven E. Protter
Exalted Contributor

Re: Sendmail CVE-2009-4565 CERT

Shalom Dorothy,

HP addresses all important CERT warnings on sendmail.

The initial response is usually a replacement for the sendmail binary file. It is then followed up, sometimes much later with a new depot based release of sendmail.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
DShinn
Frequent Advisor

Re: Sendmail CVE-2009-4565 CERT

Thank-you for the information! Probably the latest CERT will be addressed within a timely manner?

Mark Nierth
Advisor
Solution

Re: Sendmail CVE-2009-4565 CERT

Hi Dorothy,
I opened a case with HP on this CVE last month and here is their response.

I looked into the new vulnerability, CVE-2009-4565. I checked with our Level 3 group and it is a new issue. A new Service Request was started for this vulnerability and a CR, QXCR1001004856 was created. They are working on a fix.



The Level 3 people did tell me that if not using TLS / STARTLS there is no possibility of an exploit.

As of yet, I haven't seen a fix yet.

Mark
DShinn
Frequent Advisor

Re: Sendmail CVE-2009-4565 CERT

Mark,

Thank-you for posting the information! Will pass along this information to my management.

Thanks again!

Dorothy