ULTRIX SSRT035902_ULT45 DIGITAL ULTRIX V4.3 - 4.5 VAX/MIPS ECO Summary
Copyright (c) Digital Equipment Corporation 1996.
All rights reserved.
PRODUCT: DIGITAL ULTRIX, Versions 4.3 - 4.5
COMPONENT: Sendmail
SOURCE: Digital Equipment Corporation
ECO INFORMATION:
ECO Kit Name: SSRT035902_ULT45
ECO Kits Superseded by This ECO Kit: SSRT0359_ULT45
ECO Kit Approximate Size: SSRT035902_ULT45.tar 2775040 Bytes
System Reboot Necessary: Yes
ECO KIT SUMMARY:
An ECO kit exists for DIGITAL ULTRIX V4.3 - 4.5. This kit addresses the
following problems:
A potential security vulnerability has been identified with
DIGITAL ULTRIX (VAX / MIPS) V4.3 through V4.5 syslog internal buffering.
This potential vulnerability may allow users to gain
unauthorized privileges. Digital has corrected this potential
vulnerability and provided kits containing new binaries.
INSTALLATION NOTES:
This ECO is a tar image containing replacement module(s) for sendmail
and syslog.o (a module in libc.a). You will want to save the current
versions of libc.a and sendmail before installing the new, ECO version(s).
The ECO's are for 4.3, 4.3A, 4.4, and 4.5 MIPS versions and 4.3, 4.4
and 4.5 VAX versions. Once the files are extracted, there are the
following directories available:
4.3/MIPS
4.3/VAX
4.3A/MIPS
4.4/MIPS
4.4/VAX
4.5/MIPS
4.5/VAX
To install, cd to the appropriate directory, and do the following:
cp /lib/libc.a /lib/libc.save.a
ar dv /lib/libc.a syslog.o
ar rv /lib/libc.a syslog.o
ranlib /lib/libc.a
mv /usr/lib/sendmail /usr/lib/sendmail.save
cp sendmail /usr/lib/sendmail
chown root /usr/lib/sendmail
chmod 04755 /usr/lib/sendmail
This patch can be found at any of these sites:
Colorado Site
Georgia Site
Files on this server are as follows:
ssrt035902_ult45.README
ssrt035902_ult45.CHKSUM
ssrt035902_ult45.CVRLET_TXT
ssrt035902_ult45.tar
|