OBSOLETE Patch-ID# 140400-03


Download this patch from My Oracle Support

Your use of the firmware, software and any other materials contained in this update is subject to My Oracle Support Terms of Use, which may be viewed at My Oracle Support.
For further information on patching best practices and resources, please see the following links:
Copyright (c) 2012, Oracle and/or its affiliates. All rights reserved.

Keywords: security in.ftpd globbing wu_fnmatch() nscd ftp client syst
Synopsis: Obsoleted by: 144054-03 SunOS 5.10_x86: ftp and ftpd patch
Date: Jun/04/2010


Install Requirements: Reboot after installing this patch to activate the changes delivered. An alternative may be specified in the Special Install Instructions.

Solaris Release: 10_x86

SunOS Release: 5.10_x86

Unbundled Product:

Unbundled Release:

Xref: This patch available for SPARC as patch 140399

Topic: SunOS 5.10_x86: ftp and ftpd patch

Relevant Architectures: i386

Bugs fixed with this patch:

Sun CR # Bug #
507320315218433
621910415245129
623948715253568
631984415285490
649777315363328
650138815365355
651470015372953
671666815488680
694694515638815


Changes incorporated in this version: 6946945

Patches accumulated and obsoleted by this patch: 120086-02 124238-01 126259-03 128001-01

Patches which conflict with this patch:

Patches required with this patch:

Obsoleted by: 144054-03

Files included with this patch:

/usr/bin/ftp
/usr/sbin/in.ftpd

Problem Description:

6946945 CVE-2008-4247 ftpd vulnerable to CSRF
 
(from 140400-02)
 
6219104 FTP and FTPD buffers are too small, cause AD interop issues
 
(from 140400-01)
 
6716668 in.ftpd handles "LIST ." as "ls -lA *", not "ls -lA ."
 
(from 128001-01)
 
6514700 when FTP server tries to bind one of extra reserved ports, it gives up
 
(from 126259-03)
 
6497773 ftp "stou" on Solaris 10 not compliant with RFC 959
 
(from 126259-02)
 
6501388 pwd subcommand in in.ftpd truncates first 3 bytes from dirname, if dirname a symlink
 
(from 126259-01)
 
        This revision accumulates generic Sustaining patch 120086-02
        into Solaris S10U4 update.
 
(from 120086-02)
 
5073203 guest user cannot chdir to home directory if nscd is running
 
(from 120086-01)
 
6239487 in.ftpd has globbing problem in wu_fnmatch() function
 
(from 124238-01)
 
6319844 unable to suppress automatic sending of SYST command from ftp client


Patch Installation Instructions:
--------------------------------
 
Please refer to the man pages for instructions on using 'patchadd'
and 'patchrm' commands provided with Solaris.
 
The following example installs a patch to a standalone machine:
 
       example# patchadd /var/spool/patch/123456-07
 
The following example removes a patch from a standalone system:
 
       example# patchrm 123456-07
 
For additional examples please see the appropriate man pages. Any
other special or non-generic installation instructions should be
described below as special instructions.


Special Install Instructions:
-----------------------------
 
None.


README -- Last modified date: Saturday, November 10, 2012