Bug 51247

Summary: sendmail-8.10.0-aliasesDoS.patch should NOT be included
Product: [Retired] Red Hat Public Beta Reporter: Christopher McCrory <chrismcc>
Component: sendmailAssignee: Florian La Roche <laroche>
Status: CLOSED RAWHIDE QA Contact: David Lawrence <dkl>
Severity: medium Docs Contact:
Priority: medium    
Version: roswell   
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2001-08-08 19:02:53 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Christopher McCrory 2001-08-08 18:57:47 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:0.9.2) Gecko/20010725

Description of problem:
sendmail-8.10.0-aliasesDoS.patch should NOT be included

attaching emails from claus

How reproducible:
Always

Steps to Reproduce:
1.  rpm --rebuild sendmail-8...
2.
3.
	

Additional info:

Comment 1 Christopher McCrory 2001-08-08 19:02:48 UTC
This was originally from a sendmail 8.12.0 Beta build, but applies to current rpm



From Claus (@sendmail Inc.)

<snip>
> 
> [chrismcc@www1 sendmail-8.12.0.Beta7]$ head -n 1030 sendmail/main.c | 
> tail -n 7
> 
> if (LogLevel > 1)
> sm_syslog(LOG_ALERT, NOQID,
> "user %d attempted to rebuild the alias map",
> RealUid);
> usrerr("Permission denied");
> finis(FALSE, EX_USAGE);
> }


Where did you get that version? Did you patch it? That's NOT in
the version we distribute (I just verified it twice).  Please
download Beta7 from sendmail.org and verify the PGP signature.


-----
On Thu, May 24, 2001, Christopher McCrory wrote:


> > Where did you get that version? Did you patch it? That's NOT in
> > the version we distribute (I just verified it twice).  Please
> > download Beta7 from sendmail.org and verify the PGP signature.

> 
> 
> You're right.  Sorry.  It was from a aliases DOS attack patch for older 
> sendmail versions that I accidently left in place.


That code is in sendmail since 8.10.

------  END -----

I can send/attach more emails if you would like.




Comment 2 Florian La Roche 2001-08-09 12:14:24 UTC
Thanks a lot for this bug-report, fixed in next release,

Florian La Roche