SGI, Sendmail vulnerabilities patched

25.05.2006
-- SGI (http://support.sgi.com/) has issued a patch for its Advanced Linux Environment. According to Secunia, "this fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, by malicious users to cause a DoS (Denial of Service), manipulate certain information, compromise a vulnerable system, or by malicious people to use PHP as an open mail relay, gain knowledge of potentially sensitive information, conduct cross-site scripting attacks and script insertion attacks, cause a DoS, and compromise a vulnerable system."

-- An update (ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt) has been provided for Sendmail by SCO. "Sendmail could allow a remote attacker to execute arbitrary code as root, caused by a signal race vulnerability."