RE: Sun Solaris login bug patches out

From: Kain, Becki (B.) (bkain1@ford.com)
Date: 12/19/01


From: "Kain, Becki (B.)" <bkain1@ford.com>
To: "'focus-sun@securityfocus.com'" <focus-sun@securityfocus.com>
Date: Wed, 19 Dec 2001 11:35:28 -0500

Not to sound doomish, but once we've applied these patches, is there a test we can do to see if the vulnerability is gone?

thanks

-----Original Message-----
From: James Lick [mailto:jlick@drivel.com]
Sent: Friday, December 14, 2001 4:25 PM
To: focus-sun@securityfocus.com; bugtraq@securityfocus.com
Subject: Sun Solaris login bug patches out

On Fri, 14 Dec 2001, James Lick wrote:
> For the login security bug recently announced by CERT, is there any way to
> fix this currently without turning off telnet and rlogin? Much as I'd
> like to take this opportunity to force everyone to use ssh, I can't. I
> also don't have support so no t-patches for me.
 [snip]
1) The best solution, Sun has released patches today for this bug. Frank
Pellegrino replied with the most complete list:

  111085-02 SunOS 5.8: /usr/bin/login patch
  111086-02 SunOS 5.8_x86: /usr/bin/login patch
  112300-01 SunOS 5.7:: usr/bin/login Patch
  112301-01 SunOS 5.7_x86:: usr/bin/login Patch
  105665-04 SunOS 5.6: /usr/bin/login patch
  105666-04 SunOS 5.6_x86: /usr/bin/login patch
[snip]



Relevant Pages

  • Re: Mathematica problems on Solaris
    ... as some recent Solaris changes ... bug - it might well be a Mathematica bug. ... I had resisted the temptation to set up a system for testing this, but your post has inspired me, so I will do a fresh install and test it without any patches. ... Given I have no Sun contract, this probably means there were no patches on my system when I first found the problem. ...
    (comp.unix.solaris)
  • Solaris 10 patching
    ... patch aquisition method. ... I was first told to enter my Sun Online Account details. ... When it came to the patches though, ... For customers with a Sun Service plan you can make use of the free ...
    (comp.unix.solaris)
  • Sun patches broke my KVM!
    ... The patches worked great and I ... patches my KVM mouse/track-pad stopped working on all the systems! ... Sun compatible. ... connected to the systems via USB and the Monitor. ...
    (comp.sys.sun.hardware)
  • Re: Sun Patches timetable
    ... >>> installing the latest patch clusters from Sun. ... >> My team applies patches each quarter. ... >> mission critical systems, so by the time the most critical systems have ...
    (Focus-SUN)
  • Re: Solaris 10 patching
    ... security and recommended patches. ... moaning about being unable ever again to patch their systems, ... I was first told to enter my Sun Online Account details. ... without a paid up service plan. ...
    (comp.unix.solaris)