OBSOLETE Patch-ID# 144054-04
Download this patch from My Oracle Support
Your use of the firmware, software and any other materials contained
in this update is subject to My Oracle Support Terms of Use, which
may be viewed at My Oracle Support.
|
For further information on patching best practices and resources, please
see the following links:
|
Copyright (c) 2012, Oracle and/or its affiliates. All rights reserved.
|
Keywords: security in.ftpd globbing wu_fnmatch() nscd ftp client syst z
Synopsis: Obsoleted by: 144054-05 SunOS 5.10_x86: ftp and in.ftpd patch
Date: Nov/09/2010
Install Requirements: Reboot after installing this patch to activate the changes delivered. An alternative may be specified in the Special Install Instructions.
Solaris Release: 10_x86
SunOS Release: 5.10_x86
Unbundled Product:
Unbundled Release:
Xref: This patch available for SPARC as patch 144053
Topic: SunOS 5.10_x86: ftp and in.ftpd patch
Relevant Architectures: i386
Bugs fixed with this patch:
Changes incorporated in this version: 6980385
Patches accumulated and obsoleted by this patch: 120086-02 124238-01 126259-03 128001-01 140400-03
Patches which conflict with this patch:
Patches required with this patch:
Obsoleted by:
Files included with this patch:
/usr/bin/ftp
/usr/sbin/in.ftpd
Problem Description:
6980385 ftpd problems
(from 144054-03)
6927821 in.ftpd is unable to list large directories when client issues 'ls'
(from 144054-02)
This revision accumulates generic Sustaining patch 140400-03
into Solaris S10U9 update.
(from 144054-01)
This revision accumulates generic Sustaining patch 140400-02
into Solaris S10U9 update.
(from 140400-03)
6946945 CVE-2008-4247 ftpd vulnerable to CSRF
(from 140400-02)
6219104 FTP and FTPD buffers are too small, cause AD interop issues
(from 140400-01)
6716668 in.ftpd handles "LIST ." as "ls -lA *", not "ls -lA ."
(from 128001-01)
6514700 when FTP server tries to bind one of extra reserved ports, it gives up
(from 126259-03)
6497773 ftp "stou" on Solaris 10 not compliant with RFC 959
(from 126259-02)
6501388 pwd subcommand in in.ftpd truncates first 3 bytes from dirname, if dirname a symlink
(from 126259-01)
This revision accumulates generic Sustaining patch 120086-02
into Solaris S10U4 update.
(from 120086-02)
5073203 guest user cannot chdir to home directory if nscd is running
(from 120086-01)
6239487 in.ftpd has globbing problem in wu_fnmatch() function
(from 124238-01)
6319844 unable to suppress automatic sending of SYST command from ftp client
Patch Installation Instructions:
--------------------------------
Please refer to the man pages for instructions on using 'patchadd'
and 'patchrm' commands provided with Solaris.
The following example installs a patch to a standalone machine:
example# patchadd /var/spool/patch/123456-07
The following example removes a patch from a standalone system:
example# patchrm 123456-07
For additional examples please see the appropriate man pages. Any
other special or non-generic installation instructions should be
described below as special instructions.
Special Install Instructions:
-----------------------------
NOTE 1: Reboot the system after patch installation or restart FTP service.
This patch requires a reboot to restart FTP server in.ftpd(1M). Until
the process is restarted it will continue to run the older version and
may be vulnerable to any issues the patch addresses.
Restarting FTP service (in.ftpd) after installing this patch:
# svcadm restart svc:/network/ftp:default
README -- Last modified date: Saturday, November 10, 2012