|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: New Solaris root exploit for /usr/lib/lp/bin/netpr
From: Darren Moffat - Solaris Sustaining Engineering (Darren.Moffat
UK.SUN.COM)Date: Mon May 15 2000 - 11:37:43 CDT
- Next message: deepquest
NETSCAPE.NET: "forward:Update on Web Companion Issues"
- Previous message: Ultor: "Eudora Pro & Outlook Overflow - too long filenames again"
- Maybe in reply to: Anonymous: "New Solaris root exploit for /usr/lib/lp/bin/netpr"
- Next in thread: Jeremy Rauch: "Re: New Solaris root exploit for /usr/lib/lp/bin/netpr"
- Maybe reply: Darren Moffat - Solaris Sustaining Engineering: "Re: New Solaris root exploit for /usr/lib/lp/bin/netpr"
- Reply: Jeremy Rauch: "Re: New Solaris root exploit for /usr/lib/lp/bin/netpr"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
>I have not tested either of these on Solaris 8, but I am expecting it to
>be vulnerable. It also appears that Solaris 2.6 on SPARC machines may not
>be exploitable unless patch 106235-03 or patch 106235-04 is installed.
>How about that? Keep up on your patches and get owned faster. Let's hope
>that Sun puts this buffer overflow silliness to rest soon. No more buffer
>overflows will mean no more buffer overflow exploits.
I'm told by my colleagues who look after printing that this is fixed in:
5.6 SPARC T106235-05 Intel T106235-05
5.7 SPARC T107115-04 Intel T106235-04
5.8 SPARC 109320-01 Intel T109321-01
Tpatches are available only to customers with a maintenance contract until
they patches become official.
These patches will become part of the recommended patch set in due course.
-- Darren J Moffat
- Next message: deepquest
NETSCAPE.NET: "forward:Update on Web Companion Issues"
- Previous message: Ultor: "Eudora Pro & Outlook Overflow - too long filenames again"
- Maybe in reply to: Anonymous: "New Solaris root exploit for /usr/lib/lp/bin/netpr"
- Next in thread: Jeremy Rauch: "Re: New Solaris root exploit for /usr/lib/lp/bin/netpr"
- Maybe reply: Darren Moffat - Solaris Sustaining Engineering: "Re: New Solaris root exploit for /usr/lib/lp/bin/netpr"
- Reply: Jeremy Rauch: "Re: New Solaris root exploit for /usr/lib/lp/bin/netpr"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]