[12047] in bugtraq

home help back first fref pref prev next nref lref last post

Sun's TTSESSION Vulnerability

daemon@ATHENA.MIT.EDU (Bauer, Rich)
Wed Sep 29 14:57:15 1999

Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Message-Id:  <32A724D44F18D311AD900090273AC53410A54E@eclipse.rosenbluth.com>
Date:         Wed, 29 Sep 1999 09:12:19 -0400
Reply-To: "Bauer, Rich" <rbauer@ROSENBLUTH.COM>
From: "Bauer, Rich" <rbauer@ROSENBLUTH.COM>
X-To:         "bugtraq@securityfocus.com" <bugtraq@securityfocus.com>
To: BUGTRAQ@SECURITYFOCUS.COM

One of our systems administrators recently told us that Sun's fix for the
TTSESSION vulnerability (running ttsession with DES) prohibits root from
using CDE in an NISPLUS environment, and prohibits any user from using CDE
in a stand-alone environment.  Is there a patch forthcoming or some other
work-around that doesn't have these limitations ?

home help back first fref pref prev next nref lref last post