SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS, Memory Jumps, Integer Overflow)

Gadi Evron ge at
Fri Mar 24 01:28:16 UTC 2006

On Thu, 23 Mar 2006 Valdis.Kletnieks at wrote:
> Also, it would help if instead of FUD-mongering, you actually went to Claus
> (or asked somebody else to) with *specific suggestions* of how to improve the
> process.  He may be stubborn about the way he does things, but if you include
> specific changes, and show how those changes make *visible* improvements to
> the product, he'll listen.
> (visible improvements - saying "It Would Be Nice If" doesn't cut it.  On the other
> hand, replacing the IWBNI with "If X were done, then the security community would
> be able to do Y, and the network operations community could do Z, with benefits
> A, B, and C" - now *that* might get some traction...)

No offense Valdis, you know I both like you and consider you a friend,
but if you (sendmail) can't take the heat and/or stand up to the task of
being International Infrastructure, step down.

This isn't about processes, it's about something that has been around for
a while, many reply on and keeps ******* up. Where it simply can't.


