SUMMARY: Vulnerability rpc.cmsd (ivd/cn)

From: Claus Nagel <ftcn1_at_IVD.Uni-Stuttgart.DE>
Date: Fri, 23 Jul 1999 19:48:17 +0200

Hello all, 23-jul-1999

The week finishes, but I've got only one answer about the subject. So
the summary is short. I did the same what Richard (see below) did. I
comment out the rpc.cmsd line in the inetd.conf file and send a HUP-
signal to the inetd-process.

On the sly I hope COMPAQ will post a patch to CERT, like most of the
other vendors already did.

Thanks to Richard, Claus

The original question:
----------------------
> Hello, 19-jul-1999
>
> anyone heard of a patch or statement of Compaq concerning
>
> CERT Advisory CA-99.08
> (ftp.cert.org/pub/cert_advisories/CA-99-08-cmsd.txt)
>
> for CTU (Compaq Tru64 UNIX)?
>
> Any help appreciated - Thanks. I'll summarize.
> ...

The (edited) answer(s)
----------------------
> Date: Mon, 19 Jul 1999 14:17:36 -0400 (EDT)
> From: "Richard L Jackson Jr" <rjackson_at_portal.gmu.edu>
> To: ftcn1_at_IVD.Uni-Stuttgart.DE (Claus Nagel)
> Reply-To: Richard L Jackson Jr <rjackson_at_gmu.edu>
> Subject: Re: Vulnerability rpc.cmsd (ivd/cn)
> ...
> I opened a call with Compaq 7/14, sequence number C990714-66, and asked
> for the status of rpc.cmsd for CTU. I was told there are no known
> vulnerabilities with the CTU version. I have also forward the CERT
> advisory to the CSC point of contact. I don't have a warm and fuzzy and
> have disabled it from all of our Solaris, HP-UX, and Digital UNIX systems.
> ...

######################################################################
#address: University of Stuttgart, Institute of Process Engineering #
# and Power Plant Technology (IVD) #
# Claus Nagel, Pfaffenwaldring 23, D-70550 Stuttgart/Germany #
#phone: 49 711 685 -3751, -3563, -3487 . #
#fax: 49 711 685 3491 _ - |\ #
#email: nagel_at_ivd.uni-stuttgart.de - | \ #
# nagel_at_guug.de | \ */ O #
#www: http://www.ivd.uni-stuttgart.de .__|___\|_. \* #
################################################~~~~\_______/~~~~~|~##
Received on Fri Jul 23 1999 - 17:49:12 NZST

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:39 NZDT