grsecurity and latest sendmail vulnerability

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

grsecurity and latest sendmail vulnerability

Postby marcin_1 » Fri Mar 24, 2006 5:20 am

Hi,
does grsecurity protects against exploiting latest sendmail vulnerability?
http://xforce.iss.net/xforce/alerts/id/216
If yes, then what options should be turned on?

Regards.
marcin_1
 
Posts: 8
Joined: Tue Dec 17, 2002 12:10 pm

Re: grsecurity and latest sendmail vulnerability

Postby PaX Team » Sun Mar 26, 2006 11:28 am

marcin_1 wrote:Hi,
does grsecurity protects against exploiting latest sendmail vulnerability?
http://xforce.iss.net/xforce/alerts/id/216
If yes, then what options should be turned on?
it always depends on the exploit technique used and the answer is always the same: runtime code generation based exploits cannot work, the rest may (with or without having to guess randomization, depending on the nature of the bug, info leaking, whatnot).
PaX Team
 
Posts: 2310
Joined: Mon Mar 18, 2002 4:35 pm

Postby Platyna » Wed Mar 29, 2006 9:58 am

Here is a document about how to check if you are vulnerable:
http://rapturesecurity.org/jack/exploit ... dmail.html
However I would simply recommend you upgrade to newest version.

Regards.
Platyna
 
Posts: 17
Joined: Fri Jul 29, 2005 5:04 pm


Return to grsecurity support