home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.sun.admin,comp.security.misc
- From: jkimball@src.honeywell.com (John Kimball)
- Subject: INTERMIM SUMMARY: SunOS 4.1.3 and recent security patches
- Message-ID: <1992Nov4.150824.26312@src.honeywell.com>
- Organization: Honeywell Systems & Research Center
- References: <1992Oct16.161209.3142@src.honeywell.com>
- Date: Wed, 4 Nov 1992 15:08:24 GMT
-
- Thanks to everyone who replied to my request for info regarding what
- security patches (if any) needed to be applied to the new rev of SunOS,
- 4.1.3. Most of my question marks are filled in. Help came from:
-
- shawni@tis.llnl.gov (Shawn Instenes)
- Brad.Powell@Corp.Sun.COM (Brad Powell )
- "(Alain Brossard EPFL-SIC/SII)" <brossard@siisun.epfl.ch>
- jdavis@bordeaux.kpno.noao.edu (Jim Davis)
- guy@auspex.com (Guy Harris)
- zierke@rzdsun11.informatik.uni-hamburg.de (Reinhard Zierke)
- Steinar.Haug@delab.sintef.no (Steinar Haug)
- Kenneth.Pon@Corp.Sun.COM (Kenneth Pon)
-
- In particular Ken Pon says that a CWS Alert will be coming out from Sun soon
- describing the patches that have been upgraded for 4.1.3. (Some patches
- were still in the process of being upgraded.) So if you want the truly
- official scoop, wait for the alert. But in the interim, my summary is:
-
- ============================================================================
- security patches for 4.1.3
-
- patch comments what to do for 4.1.3
- -----------------------------------------------------------------------------
- 100103 file permissions <get patch rev 11>
- 100513 TIOCCONS, pty living on (CA-90:12,etc) <get rev 01>
- 100173 get root via NFS uids (CA-91:21,CA-92:15) <get rev 09>
- 100296 rpc.mountd, netgroups (CA-91:09,CA-92:12) <get rev 04>
- 100305 lpd deletes anything (CA-91:10a) <get rev 10>
- 100376 SPARC integer / and * (CA-91:16,CA-92:15) <in 4.1.3>
- 100383 rdist lets you make setuid files (CA-91:20) <get rev 05>
- 100424 fsirand and nfs handles (reqs 173) (CA-91:21) <patch forthcoming>
- 100448 OW 3.0 loadmodule gives you root (CA-91:22) <get rev 01?>
- 100478 xlock screws up <??>
- 100482 several NIS holes (CA-92:13) <get rev 03>
- 100567 icmp redirects, denial of service (CA-92:15) <get rev 04>
- 100630,100633,100377 --
- getting root via LD_ and env vars (CA-92:11) <get 377-05, ...??>
-
- I've not gone after info on the C2 Jumbo Patch, 100564, which impacts
- rpc.yppasswdd, rpc.pwdauthd -- we're not running C2 (yet).
-
- 100513 supercedes 100188 (CA-90:12), sez Ken Pons.
-
- 100633 is for Sun Shield (so we don't care), says Steve Scampani.
- ============================================================================
-
-
- John Kimball
-
- DOMAIN: jkimball@src.honeywell.com Honeywell Systems and Research Center
- postmaster@src.honeywell.com Computer Sciences/Software Technology
- UUCP: <any-smart-host>!srcsip!jkimball 3660 Technology Drive, MN65-2100
- VOICE: +1 612/951-7343 FAX: 7438 Minneapolis, MN 55418-1006
- DISCLAIMER: The only opinion Honeywell authorizes me to have is:
- "Thermostats are Good"
-
-