Great Circle Associates Firewalls
(March 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Sendmail bug
From: nsayer @ quack . kfu . com (Nick Sayer)
Organization: The Duck Pond public unix: +1 408 249 9630, log in as 'guest'.
Date: 1 Mar 1995 22:10:19 UTC
Apparently-to: firewalls @ greatcircle . com
Newsgroups: quack.firewalls
References: <199502280900 . BAA00552 @ miles . greatcircle . com>

firewalls-digest-owner @
 greatcircle .
 com writes:

>> From firewalls-owner @
 GreatCircle .
 COM Sat Feb 25 10:16 EST 1995
>> From: "Dr. Frederick B. Cohen" <fc @
 all .
 net>
>> Subject: Sendmail bug
>> To: firewalls @
 greatcircle .
 com
>> Date: Fri, 24 Feb 1995 16:36:27 -0500 (EST)
>> 
>>  I just discovered that the sendmail bug (new) works from outside on
>>  SunOS - CONTRARY TO WHAT THE CERT ADVISORY SAYS!!!
>>  
>As a matter of interest, are we talking SunOS or Solaris, as from the CERT
>advisory, it says SOLARIS isn't vulnerable, yet it publishes details of
>a patch.... I'm confused........

Without adding the version numbers, none of the above statements make
any sense at all.

Solaris 1.x contains SunOS 4.x. That is, Solaris 1.0 contains SunOS
4.1, Solaris 1.0.1 contains SunOS 4.1.1. Solaris 1.1 contains SunOS
4.1.2, Solaris 1.1.1 contains SunOS 4.1.3, Solaris 1.1.1B contains
SunOS 4.1.3_U1, and Solairs 1.1.2 contains SunOS 4.1.4.

Solaris 2.x contains SunOS 5.x. That is, Solaris 2.0 contains SunOS 5.0.
Solaris 2.1 contains SunOS 5.1. Solaris 2.2 contains SunOS 5.2. Solaris
2.3 contains SunOS 5.3. Solaris 2.4 contains SunOS 5.4.

The word 'contains' is carefully chosen. A particular rev of Solaris is
a superset, containing a version of SunOS, Openwindows, the Deskset
crap, and probably a few other things.

Just tossing out the word SunOS or Solaris has no differentiating power
at all, except that it excludes SunOS revs <4.1.

-- 
Nick Sayer <nsayer @
 quack .
 kfu .
 com>  | Anita Hill then, Paula Jones now.
N6QQQ @ N0ARY.#NOCAL.CA.USA.NOAM   | 
+1 408 249 9630, log in as 'guest' | What goes around, comes around.
URL: http://www.kfu.com/~nsayer/   | 


Indexed By Date Previous: point to point (PPP) encryptor
From: cbk @ ingress . com (Charles Kaplan)
Next: Re: packet filtering vs application based firewalls
From: rmck @ sandfiddler . paragon-systems . com (Bob McKisson)
Indexed By Thread Previous: point to point (PPP) encryptor
From: cbk @ ingress . com (Charles Kaplan)
Next: Re: Sendmail bug
From: nsayer @ quack . kfu . com (Nick Sayer)

Google
 
Search Internet Search www.greatcircle.com