On Fri, 2006-09-08 at 09:38 -0500, Gilbert Sebenste wrote: > Thanks so much for doing that! To others: the reason for me wanting the > new Sendmail so badly is that it fixes the DOS attack potential (I don't > care what anyone says, FrSirt, NVD and CVE say it's a DOS), and that is > reason enough to want that package (or at least the DOS fix backported). > > I agree as much time should be spent on FC6, but I don't see how that a > DOS isn't a DOS. Just my opinion, and if I am wrong, correct me, please. > Thanks! Well it is probably no more of a DOS in practice for a remote site to connect to your sendmail and crash a child such that the parent will start new ones as needed than to connect and talk very slowly, keeping that process busy for a long time. You can do the latter to any MTA. -- Les Mikesell lesmikesell@xxxxxxxxx