Patch-ID# 104477-04
Keywords: security in.ftpd ftp
Synopsis: SunOS 4.1.4: ftp and in.ftpd fixes
Date: Aug/26/98

Solaris Release: 1.1.2 

SunOS Release: 4.1.4

Unbundled Product: 

Unbundled Release: 

Relevant Architectures: sparc
    NOTE: sun4(all)

BugId's fixed with this patch: 1246408 1198215 4011498 4080226

Changes incorporated in this version: 4080226

Patches accumulated and obsoleted by this patch: 

Patches which conflict with this patch: 

Patches required with this patch: 

Obsoleted by: 

Files included with this patch: ftp 
				in.ftpd

Problem Description: 

4080226  Security issue: security hole in mget (on ftp client)
1246408  ftp can gain root access from port 20 to other systems 
1198215  ftp can silently lose data when writing to nfs
4011498  ftp fails with multiple access requests to the server


Patch Installation Instructions: 

1.  su root

2.  cd <patch directory>

3.  mv /usr/etc/in.ftpd /usr/etc/in.ftpd.FCS
    mv /usr/ucb/ftp /usr/ucb/ftp.FCS

4.  cp in.ftpd /usr/etc/in.ftpd
    chown root.staff /usr/etc/in.ftpd

    cp ftp /usr/ucb/ftp
    chown root.staff /usr/ucb/ftp
