From nobody  Fri Aug  8 22:32:09 1997
Received: (from nobody@localhost)
          by hub.freebsd.org (8.8.5/8.8.5) id WAA08536;
          Fri, 8 Aug 1997 22:32:09 -0700 (PDT)
Message-Id: <199708090532.WAA08536@hub.freebsd.org>
Date: Fri, 8 Aug 1997 22:32:09 -0700 (PDT)
From: pgiffuni@fps.biblos.unal.edu.co
To: freebsd-gnats-submit@freebsd.org
Subject: sendmail doesn't use smrsh by default
X-Send-Pr-Version: www-1.0

>Number:         4252
>Category:       conf
>Synopsis:       sendmail doesn't use smrsh by default
>Confidential:   no
>Severity:       serious
>Priority:       high
>Responsible:    peter
>State:          closed
>Quarter:        
>Keywords:       
>Date-Required:  
>Class:          change-request
>Submitter-Id:   current-users
>Arrival-Date:   Fri Aug  8 22:40:01 PDT 1997
>Closed-Date:    Mon Dec 27 18:40:45 PST 1999
>Last-Modified:  Mon Dec 27 18:42:34 PST 1999
>Originator:     Pedro F. Giffuni
>Release:        2.2.2-Release
>Organization:
Universidad Nacional de Colombia
>Environment:
Non-relevant
>Description:
Please use smrsh in /etc/sendmail.cf as recommended by CERT's directives.
>How-To-Repeat:
It will probably be necessary to contact the maintainer of the port(s)
that usually go into the .forward file and to sym link vacation(1).
>Fix:
Please add the proper m4 entry for both current and stable.
>Release-Note:
>Audit-Trail:
Responsible-Changed-From-To: freebsd-bugs->peter 
Responsible-Changed-By: wosch 
Responsible-Changed-When: Sun Sep 14 11:18:27 PDT 1997 
Responsible-Changed-Why:  
Sendmail security is Peter's area. 
State-Changed-From-To: open->closed 
State-Changed-By: peter 
State-Changed-When: Mon Dec 27 18:40:45 PST 1999 
State-Changed-Why:  
smrsh is too intrusive for use by default.  -current versions of sendmail 
in 3.x and 4.0 do not suffer the same sorts of problems which lead to the 
CERT advisory 
. 
>Unformatted:
