-------------------------------------------------------------------------- Turbolinux Security Advisory TLSA-2002-57 http://www/turbolinux.co.jp/security/ security-team@turbolinux.co.jp -------------------------------------------------------------------------- Sendmail Service stop of smtp server Release date : 2002-08-28 Solution: package : sendmail-8.11.6-7 sendmail-8.9.3-28 Problem Problem in the permission of the file of the /etc/mail and the /var/run subordinate. unauthorized local user can stop service of the sendmail server. Solution: Please verify version and execute the command below. # rpm -qa | grep package name When problem corresponds, please download the update package. Do the update by the using the command below. Furthermore, please execute the package number which corresponds to your version number. Without starting a new paragraph, please enter the "\ " Bunchu sign. Execution example --------------------------------------------------------------------- # rpm -Fvh Package-1.0.0-1.i586.rpm \ Package-doc-1.0.0-1.i586.rpm \ Package-devel-1.0.0-1.i586.rpm The case where rpm command is executed, please enter as follows on the command line. # rpm -Fvh package-1.0.0-1.i586.rpm package-doc-1.0.0-1.i586.rpm package-devel-1.0.0-1.i586.rpm --------------------------------------------------------------------- < Turbolinux 8 Workstation > < Turbolinux 7 Server > < Turbolinux 7 Workstation > # rpm -Fvh sendmail-8.11.6-7.i586.rpm \ sendmail-cf-8.11.6-7.i586.rpm \ sendmail-doc-8.11.6-7.i586.rpm < Turbolinux Server 6.5 > < Turbolinux Advanced Server 6 > < Turbolinux Server 6.1 > < Turbolinux Workstation 6.0 > # rpm -Fvh sendmail-8.9.3-28.i386.rpm \ sendmail-cf-8.9.3-28.i386.rpm \ sendmail-doc-8.9.3-28.i386.rpm To execute the command below after the updating the package, please modify permission to the file 600 (reading and writing execution failure other than the root). # chmod 600 /etc/mail/* # chmod 600 /etc/sendmail* Package updates: http://www.turbolinux.co.jp/update/