PATCH: Vulnerabilities in LSF

From: Greg Reid (greid@platform.com)
Date: 12/12/01


Date: 11 Dec 2001 23:45:32 -0000
From: Greg Reid <greid@platform.com>
To: bugtraq@securityfocus.com


('binary' encoding is not supported, stored as-is)

In-Reply-To: <Pine.LNX.4.10.10112051714250.19966-100000@apollo.aci.com.pl>

LSF users,

We now have a patch that addresses the issues raised by the security posting
of 5 December 2001. It is available to our customers from ftp.platform.com or
by contacting Technical Support (support@platform.com).

The patch is currently available for LSF 4.2 on all major platforms. Patches for
other platforms and versions of LSF will be made available as required.

We would also like to point out again that many of the security issues raised can be
addressed in all versions of LSF with configuration changes. We invite you to contact
Platform Technical Support to discuss your configurations and any security concerns
that you may have.

There is also an ongoing development effort to review the security issues. We
will continue to keep you posted about our status and any actions that are taken.
We continue to work directly with the original reporter.

As always, your comments and feedback are welcome.

take care,

Greg

Greg L. Reid greid@platform.com
Second-line Technical Support Manager
Platform Computing Corporation
3760 14th Avenue, Markham Phone:(905)948-4207
Ontario, Canada, L3R 3T7 Cell :(416)788-4487


Platform Technical Support
--------------------------
Email: support@platform.com
Phone: (905)948-4297
Toll Free: 1-877-444-4573



Relevant Pages

  • FW: {RTCProd#003-520-317}Windows Update Support Request
    ... support policy for Windows NT 4.0 Workstation SP6a. ... The Microsoft Support Lifecycle defines the support policies for all ... This means that after this date, Microsoft would no longer create ... security fixes for this platform, nor automatically post to WU, etc. ...
    (NT-Bugtraq)
  • RE: Vendor wants remote control of our Servers and Workstations
    ... Of course the age-old problem with security is that ... Vendor has significant access to your internal ... this vendor uses the same method to support a number ... customer and makes significant changes ... ...
    (Security-Basics)
  • [UNIX] LSF Contains Multiple Security Vulnerabilities
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... In default LSF configuration, all LSF logs are kept in the /tmp directory. ... The result is that attackers can read any file on system. ... Flaws in "lsadmin" and "badmin" executables. ...
    (Securiteam)
  • Re: The Register: OpenVMS among most-secure of operating systems
    ... >story with out of support versions of VMS/OpenVMS as well. ... >Take LAND there is no CERT advisory for LAND refering to ... You have claimed that CERT advisory counts is ... not a good measure of the relative security of a system. ...
    (comp.os.vms)
  • Re: OT: Why Truman dropped the bomb
    ... > employing their own security guards on every flight. ... > Yet what's this administration's response? ... > drugs, but they're far less dangerous than alcohol, ... I don't see support for the Iraq war ...
    (rec.music.classical.recordings)