SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS, Memory Jumps, Integer Overflow)

There are two exploit code samples I saw. There are two remote exploits
for one of them so far that are public that I know of.

Please provide reference URLs or the code, if not then stop spreading FUD.

Bugs happen, deal with them and move on.

The endless whine is more annoying (as are 20 vendor notifications for
the same bug each with their own spin/marketing, especially when they're
all Linux with a different badge)

brandon

Brandon Butterworth wrote:

There are two exploit code samples I saw. There are two remote exploits for one of them so far that are public that I know of.

Please provide reference URLs or the code, if not then stop spreading FUD.

No.

Talk to you after the first worm.

I think this is the FUD brandon is speaking of... it's not helpful, please
stop.

Brandon Butterworth wrote:

Please provide reference URLs or the code, if not then stop spreading FUD.

No.

Talk to you after the first worm.

OK. We're holding you to your word there, Gadi.

--matt@snark.net------------------------------------------<darwin><
   Moral indignation is a technique to endow the idiot with dignity.
                                                 - Marshall McLuhan

Christopher L. Morrow wrote:

I think this is the FUD brandon is speaking of... it's not helpful, please
stop.

Okay, if you insist we talk of exploits here, I take back the "talk after the first worm".

Go to the dailydave mailing list, you will see a discussion with 2 exploit codes posted thus far. One is in the works but past POC, the other is pretty much done and was also posted on FD.

So much for FUD.

One example from the discussion:

Brandon Butterworth wrote:
> > There are two exploit code samples I saw. There are two remote exploits
> > for one of them so far that are public that I know of.
>
> Please provide reference URLs or the code, if not then stop spreading FUD.

No.
Talk to you after the first worm.

That's just about as good of a statement as a demand for a phallus size
check. If you can't back up claims, it is FUD by definition. So, just like
BB wrote above:

So you really are admitting that you were simply spreading more self-aggrandizing FUD?

You may not stick to your promises, but at least you are honest about when you are lying.

matto

--matt@snark.net------------------------------------------<darwin><
   Moral indignation is a technique to endow the idiot with dignity.
                                                 - Marshall McLuhan

Brandon Butterworth wrote:
> > There are two exploit code samples I saw. There are two remote exploits
> > for one of them so far that are public that I know of.
>
> Please provide reference URLs or the code, if not then stop spreading FUD.

No.
Talk to you after the first worm.

Hopefully we're not talking about blackworm.

That's just about as good of a statement as a demand for a phallus size
check. If you can't back up claims, it is FUD by definition. So, just like
BB wrote above:

> [...] stop spreading FUD.

Gents, killfiles. This is not the only forum where this particular
topic has been questioned as nothing more than common.

-M<