ANNOUNCE: JASS 0.3.1 released

From: Alex Noordergraaf (alex.noordergraaf@sun.com)
Date: 09/18/01


Message-ID: <3BA75660.82101797@sun.com>
Date: Tue, 18 Sep 2001 10:12:48 -0400
From: Alex Noordergraaf <alex.noordergraaf@sun.com>
To: YASSP alias <secure-sol@lists.parc.xerox.com>, SecurityFocus Solaris alias <focus-sun@securityfocus.com>
Subject: ANNOUNCE: JASS 0.3.1 released

The Solaris Security Toolkit, also known as JASS, is a free tool which
can automatically secure and minimize Solaris Operating Environment
(Solaris OE) systems.

I am pleased to announce the release of version 0.3.1 on Sept 17, 2001.

The newly released Toolkit version 0.3.1 adds several new features
including:

   - Solaris 8 support through update 5 (7/01)
   - added sunfire_mf_msp* scripts from BluePrint article
     titled 'Securing the SunFire Midframe System Controller'
   - default installation with secure.driver is now
     fully 'undo'-able
   - added several new command line arguments to
     jass-execute including -H, -l, and -q
   - modified and enhanced patch application process and
     fin script
   - some minor bug fixes

For more details on these enhancements refer to the CHANGES file
included in the distributions.

As before, the Toolkit can run in standalone mode on pre-installed
systems or as part of the JumpStart(tm) installation process.

The latest Toolkit information and download source is available at:

   http://www.sun.com/security/jass

-Alex

-- 
Alex Noordergraaf              (voice) 781.442.3447
Sun EE - Sr Staff Engineer     (email) alex.noordergraaf@sun.com
BluePrints Security articles - http://sun.com/security/blueprints



Relevant Pages

  • [NEWS] Hardening Solaris for MGC
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The Media Gateway Controller product is installed on top of Solaris ... In the default installation, Solaris has several known ... Since vulnerabilities are in the underlying Operating System customers do ...
    (Securiteam)
  • [UNIX] Remote Root Exploitation of Default Solaris sadmind Setting
    ... Get your security news from a reliable source. ... its Solaris operating system to help administrators manage systems ... The sadmind daemon is used by Solstice AdminSuite applications to ... documented to some extent in Sun documentation, ...
    (Securiteam)
  • [EXPL] Solaris Xlock Heap Overflow Vulnerability (Exploit, XUSERFILESEARCHPATH)
    ... Solaris Xlock Heap Overflow Vulnerability ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... * sol_x86_xlockex.c - Proof of Concept Code for xlock heap overflow bug. ...
    (Securiteam)
  • Cisco Security Advisory: Hardening of Solaris OS for MGC
    ... Solaris operating system. ... In order to guarantee the stability of the application Cisco must ... The second issue is the security of the default Solaris installation. ...
    (Bugtraq)
  • [UNIX] William LeFebvre "top" Format String Vulnerability
    ... Get your security news from a reliable source. ... Over four years later the vulnerability ... bug and the issue has since been patched. ... OpenBSD, FreeBSD, SCO Skunkware, and Solaris have all been subject to this ...
    (Securiteam)