home *** CD-ROM | disk | FTP | other *** search
- This advisory contains INCORRECT information. Please read...
-
- mcb@net.bio.net (Michael C. Berch) writes:
- >[...]
- >Restrict shell This workaround involves modifying the sendmail
- >commands configuration file to restrict the sendmail program
- > mailer facility using the sendmail restricted shell,
- > smrsh, by Eric Allman (the original author of
- > sendmail).
- [...]
- > Programs in the allowed set should be selected
- > carefully. Mail utilities found in /etc/aliases and
- > ~/.forward files should be considered for inclusion
- > to prevent mail delivery failures (e.g. vacation,
- > procmail, and slocal). Note that it is important that
- > sites not include interpreters (e.g. /bin/sh,
- > /bin/csh, /bin/perl, /bin/uudecode, and /bin/sed) in
- > the set of allowed programs, as they may allow system
- > compromise.
-
- If you use procmail you are still exposed to the bug. More details on this
- and a partial patch will be posted in a few minutes.
-
- ---
- Alexis Rosen Owner/Sysadmin,
- PANIX Public Access Unix & Internet, NYC.
- alexis@panix.com
-
-