Subject: Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail Distribution (fwd)
To: Jeremy C. Reed <reed@reedmedia.net>
From: Manuel Bouyer <bouyer@antioche.eu.org>
List: tech-security
Date: 10/09/2002 19:47:47
On Tue, Oct 08, 2002 at 03:40:04PM -0700, Jeremy C. Reed wrote:
> I read that sendmail.8.12.6.tar.gz was trojaned on ftp.sendmail.org around
> Sept. 28 to Oct. 6.
> 
> According to CERT, this is the correct version:
> 
>      73e18ea78b2386b774963c8472cbd309 sendmail.8.12.6.tar.gz
> 
> It appears that distinfo for the sendmail pksgrc was dated Oct.3, but the
> md5 seems to be fine.

The change at oct. 3 was for an additionnal patch. the checksump for
sendmail.8.12.6.tar.gz was commited on sep 23.

-- 
Manuel Bouyer <bouyer@antioche.eu.org>
--