Operating System - HP-UX
1833480 Members
2857 Online
110052 Solutions
New Discussion

SUN's xdrmem_getbytes( ) function integer overflow vulnerability patching

 
Chern Jian Leaw
Regular Advisor

SUN's xdrmem_getbytes( ) function integer overflow vulnerability patching

HI,
Could anyone tell me what would be the impact when patches for the xdrmem_getbytes( ) Integer Overflow vulnerabilty are applied?

Are there any changes after the patch? If there are changes, are they transparent to the users?

I've tried searching around for information with regards to the impact/results when the patch is applied but found none in CERT or in securitytracker.com. Most of these sites's have posted impacts on the vulnerability, but nothing about the changes/impact when the patch is applied.

Could someone kindly enlighten me what are the changes(if any) after the patch is applied?

Thanks


3 REPLIES 3
Michael Tully
Honored Contributor

Re: SUN's xdrmem_getbytes( ) function integer overflow vulnerability patching

You might try the sun forums. One of these links might help.

http://forum.sun.com/
http://supportforum.sun.com/
http://www.sun.com/bigadmin/
www.sunmanagers.org
Anyone for a Mutiny ?
Robert-Jan Goossens
Honored Contributor

Re: SUN's xdrmem_getbytes( ) function integer overflow vulnerability patching

Hi,

You better start you search here,

https://osc-emea.eu.sun.com/OSCSW/svcportal

Hope it helps,

Robert-Jan.
Zeev Schultz
Honored Contributor

Re: SUN's xdrmem_getbytes( ) function integer overflow vulnerability patching

Well,this is hp doc for what to do:

http://www5.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&docId=200000067909365
and there are no patches yet for HP-UX.
Imho,libc and libnsl are replaced there.

Regards,

Zeev
So computers don't think yet. At least not chess computers. - Seymour Cray