FreeBSD Security Advisory FreeBSD-SA-06:13.sendmail

Yaroslav Shvets freebsd at syskit.com
Sat Mar 25 08:02:11 UTC 2006


Hello Ruslan,

Friday, March 24, 2006, 2:56:28 PM, you wrote:

>>  This doesn't change sendmail's identification string - it's still "8.13.1"
>> on RELENG_4_11, which makes detection of unpatched systems more difficult
>> to sysadmin. Wouldn't be wise to add, say, "-p1" to this string in 
>> version.c?
RE> It depends on what you think about whether it's good or not
RE> that it's undetectable.  I prefer it to be not-detectable.

After update I have seen version numbers (8.13.1 for RELENG_4_11 and
8.13.4 for RELENG_6_0). Got check for the safe version on sendmail.org
- 8.13.6 and ... rebuilt new sendmail again manually.

Some people have decided, that there was a mistake.
IMHO, it was necessary to fix version numbers.
Everyone know, how it to hide.

--
Best regards,
Yaroslav Shvets
mailto: freebsd at syskit.com
   icq: 105666




More information about the freebsd-security mailing list