best approach to address sendmail SSRT3469

From: Richard Jackson (rjackson@portal.gmu.edu)
Date: Fri Mar 07 2003 - 12:18:39 EST


Hello,

I am looking for the different approaches folks have taken to resolve
the pre-8.12.8 security issue. I realize the SSRT3469 patches are
available.

Late 1997 to early 1998 spam became a problem and sendmail 5.65
supplied with Digital UNIX did not have the features to block spam. At
the time a popular solution was to install sendmail.org's sendmail
8.8.8 with Claus Abmann's hacks.

I am curious if folks have upgraded to sendmail.org's sendmail 8.12.8
or are using the Tru64 UNIX supplied version for a large user base
email host. The disadvantage I see with using the Tru64 UNIX version
is a Tru64 UNIX upgrade could introduce a newer version of sendmail
that must be tested in addition to the Tru64 UNIX testing. Hence the
appeal of using the sendmail.org version (i.e., don't need to upgrade
sendmail with a Tru64 UNIX upgrade). The disadvantage of sendmail
8.12.x are the enhanced security features and the issues that must be
resolved to not adversely impact the existing users.

I imagine people have tried both and wonder if the experience could be
shared.

-- 
Regards,
Richard Jackson


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:49:10 EDT