Debian DSA-290-1 : sendmail-wide - char-to-int conversion
Critical Nessus Plugin ID 15127
SynopsisThe remote Debian host is missing a security-related update.
DescriptionMichal Zalewski discovered a buffer overflow, triggered by a char to int conversion, in the address parsing code in sendmail, a widely used powerful, efficient, and scalable mail transport agent. This problem is potentially remotely exploitable.
SolutionUpgrade the sendmail-wide packages.
For the stable distribution (woody) this problem has been fixed in version 8.12.3+3.5Wbeta-5.4
For the old stable distribution (potato) this problem has been fixed in version 8.9.3+3.2W-25