Bugtraq mailing list archives

Sun's TTSESSION Vulnerability


From: rbauer () ROSENBLUTH COM (Bauer, Rich)
Date: Wed, 29 Sep 1999 09:12:19 -0400


One of our systems administrators recently told us that Sun's fix for the
TTSESSION vulnerability (running ttsession with DES) prohibits root from
using CDE in an NISPLUS environment, and prohibits any user from using CDE
in a stand-alone environment.  Is there a patch forthcoming or some other
work-around that doesn't have these limitations ?


Current thread: