Link to home
Start Free TrialLog in
Avatar of shawnk
shawnk

asked on

"Fixed MIME Content-Type header field"

Good day

I get the following error message from the error log in a Solaris 9 system. Is this an misconfiguration error or bug? If so, how do I fix this? Thank you.

Aug 27 15:39:29 mail sendmail[25528]: [ID 801593 mail.alert] i7RNdE8R025486: Fixed MIME Content-Type header field (possible attack)
Avatar of PsiCop
PsiCop
Flag of United States of America image

Well, you didn't bother to say exactly which version of sendmail you're running, but if you're running the one that came with the stock Solaris v9 install (even patched), be aware that its almost certainly an older sendmail version. Telnet to the machine's port 25 and take a look at what version is reported. If its not v8.12.11 or v8.13.x, then you're running a older version. If its v8.11.x or earlier, then its a VULNERABLE older version and you should update immediately (or at the very least change the config so it doesn't broadcast to everyone who connects it just how bad off it is).

What the error means is that as sendmail processed a message header, probably an incoming one, it saw a suspicious MIME Content-Type header field, one that may have been part of an attack on your system. What specific attack I dunno. Perhaps an attempt to get sendmail to hang. You'd have to track down the message via the logs and examine it.
First things first, check your sendmail version, and if its outdated (personally, I'd call anything earlier than v8.12.10 "outdated"), you should start working on updating it. I know that a package for v8.12.11 (the last v8.12 release) is available on http://sunfreeware.com. I imagine that v8.13 is as well, and if it isn't, you can download the source from http://www.sendmail.org

Recommended reference: _Sendmail,_3rd Edition_ by Bryan Costales, ISBN 1-56592-839-3. Its not a "How to" or "For Dummies" book, its a reference for sendmail's features and functions.
ASKER CERTIFIED SOLUTION
Avatar of jlevie
jlevie

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial