[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Security Hardening Package - final thoughts?



----- Original Message -----
Subject: Re: [cobalt-users] Security Hardening Package - final thoughts?


> cobalt raq4 wrote:
>
> > The package sets bind back to 8.2.3 for those who have updated. ( a
> > vulnerable version ) are we ok to just update it with the 8.3.3 tarball
from
> > the bind site.
>
> If you do you'll lose the Immunix StackGuard protection applied to
> Bind.  I don't know if Sun Cobalt has fixed the vulnerabilities in
> 8.2.3, so I can't tell you.

Would *anyone* (from Sun?) please speak up about 8.2.3 yes or no VULNERABLE?
I read this list pretty well and I still have yet to see a definitive answer.
The closest I've seen is, *maybe* depends on what Sun did to their pkg
version?

Been bitten once by the bind vuln.- trying to avoid this again,

Dave~