[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-users] Security Hardening Package - final thoughts?
- Subject: Re: [cobalt-users] Security Hardening Package - final thoughts?
- From: "Dave~" <cobaltraq4@xxxxxxx>
- Date: Thu Aug 8 22:58:00 2002
- List-id: Mailing list for users to share thoughts on Sun Cobalt products. <cobalt-users.list.cobalt.com>
----- Original Message -----
Subject: Re: [cobalt-users] Security Hardening Package - final thoughts?
> cobalt raq4 wrote:
>
> > The package sets bind back to 8.2.3 for those who have updated. ( a
> > vulnerable version ) are we ok to just update it with the 8.3.3 tarball
from
> > the bind site.
>
> If you do you'll lose the Immunix StackGuard protection applied to
> Bind. I don't know if Sun Cobalt has fixed the vulnerabilities in
> 8.2.3, so I can't tell you.
Would *anyone* (from Sun?) please speak up about 8.2.3 yes or no VULNERABLE?
I read this list pretty well and I still have yet to see a definitive answer.
The closest I've seen is, *maybe* depends on what Sun did to their pkg
version?
Been bitten once by the bind vuln.- trying to avoid this again,
Dave~