OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Date: Mon Jan 28 2002 - 16:30:09 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    *******************************************************************************
    * *
    * This is a newly released patch... *
    * *
    * Online links can be found at *
    * http://ftp.support.compaq.com/patches/public/unix/v4.0d/duv40db17-c0061401-12858-e-20020115.README
    *******************************************************************************

    TITLE: Tru64 UNIX V4.0d+PK9 BL17 Security Vulnerability ECO Summary

    New Kit Date: 28-JAN-2002
    Modification Date: Not Applicable
    Modification Type: New Kit: Early Release Patch Kit (ERP)

    Copyright (c) Compaq Computer Corporation 2002. All rights reserved.

    PRODUCT: Tru64 UNIX [R] 4.0D
    SOURCE: Compaq Computer Corporation

    ECO INFORMATION:

         ECO Name: DUV40DB17-C0061401-12858-E-20020115.tar
         ECO Kit Approximate Size: 4.2MB
         Kit Applies To: Tru64 UNIX 4.0D with PK9 (BL17) installed

    Checksums for DUV40DB17-C0061401-12858-E-20020115.tar:

    /usr/bin/sum results:
      62466 4080

    /usr/bin/cksum results:
      256127601 4177920

    MD5 results:
      72eafcd6df384542092bd6506365a74c

    SHA1 results:
      327d89c9f1c777f386717b0da8d00e803e910e8a

    ECO KIT SUMMARY:

    An update ECO kit exists for Tru64 UNIX 4.0D. This is an early release,
    dupatch-based, patch kit that contains solutions to security vulnerabilities
    reported in SSRT1-41U, SSRT0742U, and SSRT0759U.

    The Patch Kit Installation Instructions document and the Patch Summary and
    Release Notes document provide patch kit installation and removal instructions
    and a summary of each patch. Please read through these documents prior to
    installing patches on your system.

    INSTALLATION NOTES:

    Install this kit with the dupatch utility that is included in the patch
    kit. You may need to baseline your system if you have manually changed
    system files on your system. The dupatch utility provides the baselining
    capability.

    The prerequisite for installing this patch kit is that you must have
    installed Tru64 UNIX 4.0D and PK9 (BL17).

    KNOWN PROBLEMS WITH THE PATCH KIT:

    None.

    RELEASE NOTES FOR DUV40DB17-C0061401-12858-E-20020115:

         This document summarizes the contents and special instructions for the
         Digital UNIX V4.0D patches contained in this kit.

         For information about installing or removing patches, baselining,
         and general patch management, see the Patch Kit Installation
         Instructions document.

    1 Release Notes

    This Early Release Patch Kit Distribution contains:

       - fixes that resolve the problem(s) reported in:
            o SSRT0742U SSRT0759U SSRT1-40U SSRT1-41U SSRT1-42U SSRT1-45U SSRT1-48U
                 * for Digital UNIX V4.0D DUV40DAS0009-20010724.tar (BL17)

     The patches in this kit are being released early for general customer use.
     Refer to the Release Notes for a summary of each patch and installation
     prerequisites.

     Patches in this kit are installed by running dupatch from the directory
     in which the kit was untarred. For example, as root on the target system:

    > mkdir -p /tmp/CSPkit1
    > cd /tmp/CSPkit1
    > <copy the kit to /tmp/CSPkit1>
    > tar -xpvf DUV40D13-C0044900-1285-20000328.tar
    > cd patch_kit
    > ./dupatch

    2 Special Instructions

    There are no special instructions for Digital UNIX V4.0D Patch C614.01
    There are no special instructions for Digital UNIX V4.0D Patch C615.00
    There are no special instructions for Digital UNIX V4.0D Patch C616.01
    There are no special instructions for Digital UNIX V4.0D Patch C617.01
    There are no special instructions for Digital UNIX V4.0D Patch C618.01
    There are no special instructions for Digital UNIX V4.0D Patch C619.00

    3 Summary of CSPatches contained in this kit

    Digital UNIX V4.0D

    PatchId Summary Of Fix
    ----------------------------------------
    C614.01 SSRT1-40U,SSRT1-41U,SSRT1-42U,SSRT1-45U,SSRT1-48U
    C615.00 Security,SSRT1-40U,SSRT1-41U,SSRT1-42U,SSRT1-45U,SSRT1-48U
    C616.01 Security,SSRT1-40U,SSRT1-41U,SSRT1-42U,SSRT1-45U,SSRT1-48U
    C617.01 Security,SSRT1-40U,SSRT1-41U,SSRT1-42U,SSRT1-45U,SSRT1-48U
    C618.01 SSRT1-40U,SSRT1-41U,SSRT1-42U,SSRT1-45U,SSRT1-48U
    C619.00 SSRT1-40U,SSRT1-41U,SSRT1-42U,SSRT1-45U,SSRT1-48U

    4 Additional information from Engineering

    None

    5 Affected system files
    This patch delivers the following files:

    Digital UNIX V4.0D
            Patch C614.01
                    ./usr/bin/sh
                            CHECKSUM: 33700 176
                            SUBSET: OSFBASE425
                    ./usr/bin/ksh
                            CHECKSUM: 25688 320
                            SUBSET: OSFBASE425
                    ./usr/bin/csh
                            CHECKSUM: 31612 304
                            SUBSET: OSFBASE425
                    ./usr/bin/Rsh
                            CHECKSUM: 33700 176
                            SUBSET: OSFBASE425
                    ./usr/bin/posix/sh
                            CHECKSUM: 25688 320
                            SUBSET: OSFBASE425
                    ./sbin/.upd..sh
                            CHECKSUM: 52185 312
                            SUBSET: OSFBASE425
                    ./sbin/.upd..Rsh
                            CHECKSUM: 52185 312
                            SUBSET: OSFBASE425
                    ./usr/bin/calendar
                            CHECKSUM: 10316 4
                            SUBSET: OSFBASE425
                    ./usr/sbin/setup
                            CHECKSUM: 17956 14
                            SUBSET: OSFBASE425
                    ./sbin/it.d/bin/load_usr_pak
                            CHECKSUM: 06112 2
                            SUBSET: OSFBASE425
                    ./sbin/it
                            CHECKSUM: 06112 2
                            SUBSET: OSFBASE425
                    ./sbin/init.d/.mrg..rmtmpfiles
                            CHECKSUM: 08044 6
                            SUBSET: OSFUnknown
                    ./usr/bin/crashdc
                            CHECKSUM: 06257 8
                            SUBSET: OSFBASE425
                    ./usr/sbin/nissetup
                            CHECKSUM: 49458 36
                            SUBSET: OSFCLINET425
                    ./usr/sbin/ypsetup
                            CHECKSUM: 49458 36
                            SUBSET: OSFCLINET425
                    ./usr/sbin/cron
                            CHECKSUM: 22682 80
                            SUBSET: OSFBASE425
                    ./usr/lbin/mkstemp
                            CHECKSUM: 45630 32
                            SUBSET: OSFUnknown
                    ./usr/bin/gentapes
                            CHECKSUM: 48793 21
                            SUBSET: OSFBASE425
                    ./usr/bin/kits
                            CHECKSUM: 07519 7
                            SUBSET: OSFBASE425
                    ./usr/sbin/create_setupconf
                            CHECKSUM: 18745 3
                            SUBSET: OSFBASE425
                    ./usr/sbin/svcsetup
                            CHECKSUM: 64843 11
                            SUBSET: OSFCLINET425
                    ./usr/sys/bin/mktape
                            CHECKSUM: 40134 21
                            SUBSET: OSFBINCOM425
                    ./usr/lib/nls/msg/en_US.ISO8859-1/sh.cat
                            CHECKSUM: 63623 4
                            SUBSET: OSFBASE425
                    ./usr/lib/nls/msg/en_US.ISO8859-1/mkstemp.cat
                            CHECKSUM: 46601 1
                            SUBSET: OSFUnknown
                    ./usr/lib/nls/msg/en_US.ISO8859-1/cron.cat
                            CHECKSUM: 26825 9
                            SUBSET: OSFBASE425
                    ./sys/BINARY/std_kern.mod
                            CHECKSUM: 14892 1163
                            SUBSET: OSFBIN425
                    ./usr/sbin/bindsetup
                            CHECKSUM: 51531 34
                            SUBSET: OSFCLINET425
                    ./usr/bin/gendisk
                            CHECKSUM: 36187 18
                            SUBSET: OSFBASE425
                    ./usr/lib/nls/msg/en_US.ISO8859-1/ksh.cat
                            CHECKSUM: 41240 6
                            SUBSET: OSFBASE425
                    ./sys/BINARY/proc.mod
                            CHECKSUM: 12357 4
                            SUBSET: OSFBIN425
                    ./sbin/it.d/bin/gettimezone
                            CHECKSUM: 33633 7
                            SUBSET: OSFBASE425
                    ./sbin/init.d/.new..rmtmpfiles
                            CHECKSUM: 23974 2
                            SUBSET: OSFBASE425
                    ./usr/bin/crontab
                            CHECKSUM: 25653 56
                            SUBSET: OSFBASE425
                    ./usr/sbin/mailsetup
                            CHECKSUM: 58353 68
                            SUBSET: OSFBASE425
                    ./sbin/kreg
                            CHECKSUM: 60565 7
                            SUBSET: OSFBASE425
                    ./usr/bin/newinv
                            CHECKSUM: 26264 5
                            SUBSET: OSFBASE425
                    ./usr/sys/bin/btcreate
                            CHECKSUM: 41859 145
                            SUBSET: OSFBINCOM425
                    ./usr/lib/nls/msg/en_US.ISO8859-1/csh.cat
                            CHECKSUM: 28864 6
                            SUBSET: OSFBASE425
                    ./sys/BINARY/vfs.mod
                            CHECKSUM: 13830 393
                            SUBSET: OSFBIN425
                    ./usr/sys/bin/procprod
                            CHECKSUM: 32912 200
                            SUBSET: OSFBINCOM425
                    ./usr/sys/include/sys/fcntl.h
                            CHECKSUM: 43213 12
                            SUBSET: OSFBINCOM425
            Patch C615.00
                    ./usr/dt/bin/lp_default
                            CHECKSUM: 59279 2
                            SUBSET: OSFCDEDT425
            Patch C616.01
                    ./etc/namedb/bin/make_hosts
                            CHECKSUM: 27445 10
                            SUBSET: OSFINET425
            Patch C617.01
                    ./usr/sbin/sys_check
                            CHECKSUM: 10054 646
                            SUBSET: OSFBASE425
            Patch C618.01
                    ./usr/lbin/spell/compress
                            CHECKSUM: 45333 3
                            SUBSET: OSFDCMTEXT425
            Patch C619.00
                    ./usr/sbin/secauthmigrate
                            CHECKSUM: 41556 11
                            SUBSET: OSFC2SEC425

    [R] UNIX is a registered trademark in the United States and other countries
    licensed exclusively through X/Open Company Limited.

    Copyright Compaq Computer Corporation 2002. All Rights reserved.

      This software is proprietary to and embodies the confidential technology
      of Compaq Computer Corporation. Possession, use, or copying of this
      software and media is authorized only pursuant to a valid written license
      from Compaq or an authorized sublicensor.

           This ECO has not been through an exhaustive field test process.
           Due to the experimental stage of this ECO/workaround, Compaq
           makes no representations regarding its use or performance. The
           customer shall have the sole responsibility for adequate protection
           and back-up data used in conjunction with this ECO/workaround.

    ---