OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Casper Dik (Casper.DikSun.COM)
Date: Tue Dec 18 2001 - 13:17:26 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    >Does anyone know whether SunOS 4.x is vulnerable to the /bin/login
    >buffer overflow problem? CERT's CA-2001-34 lists "Solaris 8 and earlier"
    >as vulnerable. It's not clear to me whether this includes SunOS 4.x,
    >(which at some point was part of Solaris 1.x).
    >

    No, it does not include releases prior to 2.0 (as those are
    not SysV derived and don't have the env parsing on the
    command line)

    Casper