sendmail 8.14 has a serious memory corruption bug in it

Petr Janda elekktretterr at exemail.com.au
Tue Feb 19 17:26:47 PST 2008


On Wed, 20 Feb 2008 11:50:22 am Bill Hacker wrote:

> Sendmail fits better than most for low/no admin to JFW at getting logs
> off-box and fit licensing parameters.
>
> Those implementing a full-bore MTA for serious use will make 'a'
> selection on the criteria dearest to them, and that has naught to do
> with what is/is not in base anyway.
>

I don't think that answers the question why does Sendmail, a full blown mail 
daemon, with a long history of security issues have to be in the base: if DMA 
can satisfy for local mail delivery - required by some maintenance scripts, 
and would incidently be easier to maintain due to its small size. I think the 
very limited man power in DragonFly should be directed at writing new 
software, and not at updating old buggy and archaic software, which can be 
maintained elsewhere by others (ie. pkgsrc). 

Isnt this the reason DMA was written anyway?

Petr





More information about the Kernel mailing list