[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Security Hardening Package - final thoughts?



cobalt raq4 wrote:

> The package sets bind back to 8.2.3 for those who have updated. ( a
> vulnerable version ) are we ok to just update it with the 8.3.3 tarball from
> the bind site.

If you do you'll lose the Immunix StackGuard protection applied to
Bind.  I don't know if Sun Cobalt has fixed the vulnerabilities in
8.2.3, so I can't tell you.

> Anything else to think about before installation. ( Its gonna be a busy day
> anyway, could do without any problems )

Let us know how it went when you've finished <smile>.

I'm currently preparing a white-paper on SHP and it's intended and
unintended effects; I'll announce it here, on cobalt-developers and on
cobalt-security when it's ready, later tonight.

Jeff
-- 
Jeff Lasman <jblists@xxxxxxxxxxxxx>
Linux and Cobalt/Sun/RaQ Consulting
nobaloney.net, P. O. Box 52672, Riverside, CA  92517
voice: +1 909 778-9980  *  fax: +1 909 548-9484