Bugtraq mailing list archives

Re: Exploit of rpc.cmsd


From: casper () HOLLAND SUN COM (Casper Dik)
Date: Wed, 14 Jul 1999 23:40:26 +0200


Many people told me that they couldn't find the patches.
Not even the one that was supposed to have been released a week ago.

The following patches have now been released:

     107022-03       CDE 1.3 (Solaris 7/SPARC)

These patches should show up on SunSolve shortly;  (Ok, so I should have known
Aleph posts quicker than Sun's patch process)

Solaris 2.4 is vulnerable, AFAIK, but the patches for it haven't been
finished yet.

     

Already released was (one week ago):

     105566-08       CDE 1.2 (Solaris 2.6/SPARC)

*Where* have they been released?

This is a typo; the x86 patch is rev -08 but the same patch as SPARC patch
is rev -07, make that:

        105566-07       CDE 1.2 (Solaris 2.6/SPARC)

which is available on SunSolve.

Sorry for the confusion; I should have checked SunSolve prior to
mailing Aleph.

Patches will be available on the public patch sites shortly.

Casper


Current thread: