I installed a patched Sendmail package last week, correcting the recent vulnerability.
Sendmail.org provided a simple patch for all 8.12.x Sendmail sources that corrected this vulnerability. I added the patch to the FreeBSD package directory on the build system and created a new sendmail package (sendmail-sasl-8.12.6_4ecs) for installation on KE.
Posted by Rowan Littell at September 23, 2003 09:14 AM