OBSOLETE Patch-ID# 140400-03
Download this patch from My Oracle Support
Your use of the firmware, software and any other materials contained
in this update is subject to My Oracle Support Terms of Use, which
may be viewed at My Oracle Support.
|
For further information on patching best practices and resources, please
see the following links:
|
Copyright (c) 2012, Oracle and/or its affiliates. All rights reserved.
|
Keywords: security in.ftpd globbing wu_fnmatch() nscd ftp client syst
Synopsis: Obsoleted by: 144054-03 SunOS 5.10_x86: ftp and ftpd patch
Date: Jun/04/2010
Install Requirements: Reboot after installing this patch to activate the changes delivered. An alternative may be specified in the Special Install Instructions.
Solaris Release: 10_x86
SunOS Release: 5.10_x86
Unbundled Product:
Unbundled Release:
Xref: This patch available for SPARC as patch 140399
Topic: SunOS 5.10_x86: ftp and ftpd patch
Relevant Architectures: i386
Bugs fixed with this patch:
Changes incorporated in this version: 6946945
Patches accumulated and obsoleted by this patch: 120086-02 124238-01 126259-03 128001-01
Patches which conflict with this patch:
Patches required with this patch:
Obsoleted by: 144054-03
Files included with this patch:
/usr/bin/ftp
/usr/sbin/in.ftpd
Problem Description:
6946945 CVE-2008-4247 ftpd vulnerable to CSRF
(from 140400-02)
6219104 FTP and FTPD buffers are too small, cause AD interop issues
(from 140400-01)
6716668 in.ftpd handles "LIST ." as "ls -lA *", not "ls -lA ."
(from 128001-01)
6514700 when FTP server tries to bind one of extra reserved ports, it gives up
(from 126259-03)
6497773 ftp "stou" on Solaris 10 not compliant with RFC 959
(from 126259-02)
6501388 pwd subcommand in in.ftpd truncates first 3 bytes from dirname, if dirname a symlink
(from 126259-01)
This revision accumulates generic Sustaining patch 120086-02
into Solaris S10U4 update.
(from 120086-02)
5073203 guest user cannot chdir to home directory if nscd is running
(from 120086-01)
6239487 in.ftpd has globbing problem in wu_fnmatch() function
(from 124238-01)
6319844 unable to suppress automatic sending of SYST command from ftp client
Patch Installation Instructions:
--------------------------------
Please refer to the man pages for instructions on using 'patchadd'
and 'patchrm' commands provided with Solaris.
The following example installs a patch to a standalone machine:
example# patchadd /var/spool/patch/123456-07
The following example removes a patch from a standalone system:
example# patchrm 123456-07
For additional examples please see the appropriate man pages. Any
other special or non-generic installation instructions should be
described below as special instructions.
Special Install Instructions:
-----------------------------
None.
README -- Last modified date: Saturday, November 10, 2012