ADSM-L

Re: For those Security conscious people running AIX

2002-04-02 17:09:57
Subject: Re: For those Security conscious people running AIX
From: David Longo <David.Longo AT HEALTH-FIRST DOT ORG>
Date: Tue, 2 Apr 2002 17:09:39 -0500
Apparently not.  I have ML 09 plus a couple of security patches and 
I just checked with instfix and IY26443 is not included.  I think ML08
or ML 09 had a "telnet" security patch.

David Longo

>>> CABANL AT MODOT DOT NET 04/02/02 01:40PM >>>
Isn't/Wasn't this taken care of in ML8?



                    Gabriel Wiley
                    <wileyg AT US DOT IBM       To:     ADSM-L AT VM.MARIST DOT 
EDU 
                    .COM>                cc:
                    Sent by:             Subject:     For those Security 
conscious people running AIX
                    "ADSM: Dist
                    Stor Manager"
                    <ADSM-L AT VM DOT MAR 
                    IST.EDU>


                    04/02/2002
                    12:14 PM
                    Please respond
                    to "ADSM: Dist
                    Stor Manager"






If you are not aware .. FYI ****

SECURITY: MULTIPLE BUFFER OVERFLOW VULNERABILITIES IN TSMLOGIN

Created:    01/04/2002 at 03:22 PM


  Published Date:                      01/04/2002






  OS or Applications Affected:         AIX

  Versions Affected:                   4.3





  Severity:                            Medium





  APAR/Patch ID:                       IY26443

  Workaround Available?:               No









Run this command to see if you have it ;

instfix -ik IY26443

      or

instfix -ick IY26443

Keyword:Fileset:ReqLevel:InstLevel:Status:Abstract
Y26443:bos.rte.security:4.3.3.79:4.3.3.79:=:SECURITY: Multiple buffer
overflow vulnerabilities in tsmlogin


Gabriel C. Wiley
ADSM/TSM Administrator
AIX Support
Phone 1-614-308-6709
Pager  1-877-489-2867
Fax      1-614-308-6637
Cell       1-740-972-6441

Siempre Hay Esperanza



"MMS <health-first.org>" made the following
 annotations on 04/02/02 17:23:36
------------------------------------------------------------------------------
---
This message is for the named person's use only.  It may contain This message 
is for the named person's use only.  It may contain confidential, proprietary, 
or legally privileged information.  No confidentiality or privilege is waived 
or lost by any mistransmission.  If you receive this message in error, please 
immediately delete it and all copies of it from your system, destroy any hard 
copies of it, and notify the sender.  You must not, directly or indirectly, 
use, disclose, distribute, print, or copy any part of this message if you are 
not the intended recipient.  Health First reserves the right to monitor all 
e-mail communications through its networks.  Any views or opinions expressed in 
this message are solely those of the individual sender, except (1) where the 
message states such views or opinions are on behalf of a particular entity;  
and (2) the sender is authorized by the entity to give such views or opinions.

==============================================================================