[2250] in bugtraq
Re: [8lgm]-Advisory-22.UNIX.syslog.2-Aug-1995
daemon@ATHENA.MIT.EDU (Doug Hughes)
Tue Sep 19 09:07:12 1995
Date: Mon, 18 Sep 1995 10:53:05 -0500
Reply-To: Bugtraq List <BUGTRAQ@CRIMELAB.COM>
From: Doug Hughes <Doug.Hughes@Eng.Auburn.EDU>
X-To: BUGTRAQ@CRIMELAB.COM
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@CRIMELAB.COM>
In-Reply-To: <9509181249.ZM11707@baby>
>I just called local Sun support. They don't know anything about this
>hole and they don't accept the 8lgm advisory as problem report as we
>cannot prove that the bug exists on *our* SunOS host. Outch! I cannot
>believe that nobody else has opened a service call or bug fix request
>(or whatever Sun calls this) at Sun Microsystems. They referred me to
>patch 100909-03 which fixed a hole in syslogd for SunOS 4.1.3...
>
>My questions are:
>
>- Is there an official patch from Sun and what's the patch-ID?
>- Has anybody talked to Sun about this problem?
>- Is Sun working on a patch?
>
The person you talked to had no idea what he/she was talking about. There
is an open BUG report and tracking number. I am on a list for updates to
this report (since the bug has been reported there have not been any updates).
There is no current patch to my knowledge, but they are working on it.
I, or somebody else, will probably post updates here as they become available.
Until then, I've put my own patch together using the shlib.etc stuff,
a free snprintf, and a patched up syslog.c.
--
____________________________________________________________________________
Doug Hughes Engineering Network Services
System/Net Admin Auburn University
doug@eng.auburn.edu
Apple T-shirt on Win95 - "Been there, done that"