home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: alt.security
- Path: sparky!uunet!munnari.oz.au!mips!decwrl!sdd.hp.com!wupost!darwin.sura.net!ukma!nsisrv!nssdca.gsfc.nasa.gov!tencati
- From: tencati@nssdca.gsfc.nasa.gov (NSI Security Manager +1-202-434-4541)
- Subject: Re: CERT ADVISORY - Multiple SunOS Vulnerabilities
- Message-ID: <24JUL199210493243@nssdca.gsfc.nasa.gov>
- News-Software: VAX/VMS VNEWS 1.41
- Sender: usenet@nsisrv.gsfc.nasa.gov (Usenet)
- Nntp-Posting-Host: nssdca.gsfc.nasa.gov
- Organization: NASA - Goddard Space Flight Center
- References: <9207211919.AA20501@tictac.cert.org> <1992Jul22.154650.9967@jarvis.csri.toronto.edu> <Brtn3n.1FE@ux1.cso.uiuc.edu> <1992Jul23.113003.24332@jarvis.csri.toronto.edu>
- Date: Fri, 24 Jul 1992 15:49:00 GMT
- Lines: 33
-
- In article <1992Jul23.113003.24332@jarvis.csri.toronto.edu>, flaps@dgp.toronto.edu (Alan J Rosenthal) writes...
-
- >Ok, but I'm still wondering how important the patch is. The CERT advisory said
- >something fairly nasty, like "everyone can become root". Does this apply to
- >the *differences* between the new patch and the old patch? Like, if a site I
- >know (which for obvious reasons shall remain nameless, but it isn't at dgp) has
- >installed the old jumbo patch but doesn't install the new one, can "everyone
- >become root" or whatever the advisory said?
- >
- CERT wrote their bulletin based on an alert that Sun released. CERT
- is merely relaying that information to you. The vendor is being
- responsive and responsible. There are bugs in some of their old
- patches, and there are some new patches available, all of which fix
- holes that could let an intruder into your system with root priviliges.
-
- CERT, and other FIRST members, are merely doing a public service by
- alerting the user community to something that the vendor felt was
- serious enough to warrant the release of an alert. Decide for yourself
- how important these patches are.
-
-
- Ron Tencati
- Security Manager
- NASA Science Internet
-
- ------------------------------------------------------------------------------
- NASA Science Internet (TCP/IP & DECnet)| NSI/IP: Tencati@Nssdca.Gsfc.Nasa.Gov
- Security and Incident Response Office | NSI/SPAN: NCF::TENCATI/15548::TENCATI
- Suite 950 | Tele - +1-202-434-4541
- 700 Thirteenth St., NW | FAX - +1-202-434-4599
- Washington, D.C. 20005; USA | Beeper +1-800-759-7243, Pin:5460866
- ------------------------------------------------------------------------------
-
-