[12047] in bugtraq
Sun's TTSESSION Vulnerability
daemon@ATHENA.MIT.EDU (Bauer, Rich)
Wed Sep 29 14:57:15 1999
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Message-Id: <32A724D44F18D311AD900090273AC53410A54E@eclipse.rosenbluth.com>
Date: Wed, 29 Sep 1999 09:12:19 -0400
Reply-To: "Bauer, Rich" <rbauer@ROSENBLUTH.COM>
From: "Bauer, Rich" <rbauer@ROSENBLUTH.COM>
X-To: "bugtraq@securityfocus.com" <bugtraq@securityfocus.com>
To: BUGTRAQ@SECURITYFOCUS.COM
One of our systems administrators recently told us that Sun's fix for the
TTSESSION vulnerability (running ttsession with DES) prohibits root from
using CDE in an NISPLUS environment, and prohibits any user from using CDE
in a stand-alone environment. Is there a patch forthcoming or some other
work-around that doesn't have these limitations ?