Critical flaw in Sendmail's could give hackers full access to affected networks
Sendmail flaw could allow attackers to take complete control of affected machines

Critical flaw found in Sendmail

Patch immediately or get hacked, warns security expert

Written by Iain Thomson

A critical flaw has been found in Sendmail's popular open source SMTP server software which could give hackers full access to affected networks.

In order to exploit this vulnerability, an attacker only needs to be able to connect to the Sendmail SMTP server over a network.

Exploitation could allow attackers to take complete control of affected machines and obtain full access to users' emails, confidential information and other sensitive data on the network.

"Due to its high popularity and extensive deployment throughout the internet, this vulnerability represents a serious risk to organisations that rely on Sendmail for email services," said Gunter Ollmann, director of ISS X-Force, which discovered the flaw.

"Since SMTP is one of the few listening services allowed consistently through perimeter firewalls, we expect that many attackers will develop techniques to exploit the vulnerability in order to gain entry into corporate and government networks."

ISS X-Force has published an advisory about the flaw on its website.

Sendmail is urging all users of version 8.0 of its software to apply the patch on its website or to upgrade to the latest version of the software.

Tags:

Further reading

Much loved router software Sendmail goes commercial

by John Geralds in Silicon Valley   More...

IBM tries to knock out Sendmail email server with open source rival

by Dominique Deckmyn in Silicon Valley   More...

Tech giants team up to fight spam

Big names introduce email sender authentication products   More...

Related articles

Debian flaw exposes communications breakdown

A wake up call for open source developers, Gartner warns   More...

Sun patches 'critical' Java flaws

Problems with JDK, JRE and SDK   More...

VMware issues 'critical' security alert

Major problem with shared folders   More...

Hackers eye open source coding tools

Security firm warns of 'cross-build injection vulnerability'   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement