March 2007
SUN(SM) ALERT WEEKLY SUMMARY REPORT Week of 11-Feb-2007 - 17-Feb-2007
ID: 75
Ref: 017/2007
Date: 07 March 2007:18:41:38
Version: 1
Title: SUN(SM) ALERT WEEKLY SUMMARY REPORT Week of 11-Feb-2007 - 17-Feb-2007
Abstract: Newly Released Sun Alert Notifications - a weekly listing of newly released and updated Sun Alert Notifications.
Vendors affected: Sun
Operating systems affected: Sun
Welcome to the Sun(SM) Alert Weekly Summary Report, the newsletter that provides you with a weekly listing of newly released and updated Sun Alert Notifications. It is being distributed to inform you about critical hardware and software issues that could impact the availability, security, and data integrity of your computing environment.
==================================================================
ISSUE HIGHLIGHTS
* Newly Released Sun Alert Notifications
* Updated Sun Alert Notifications
* Additional Sun Alert Information
* Changes to Patch Access on SunSolve
==================================================================
-------------------------------------------------------------------
Newly Released Sun Alert Notifications
-------------------------------------------------------------------
(Total Released: 7)
Sun Alert ID: 102776 (RESOLVED)
Synopsis: Cisco MDS 9000 FC Generation 1 Port Module May Fail
Following a Firmware Upgrade or Service Procedure
Product: Cisco MDS 9509, Cisco MDS 9216, Cisco MDS 9513,
Cisco MDS 9216A
Category: Availability
Date Released: 15-Feb-2007
Date Closed: 16-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102776-1
-------------------------------------------------------------------
Sun Alert ID: 102796 (RESOLVED)
Synopsis: A Security Vulnerability in the TCP Implementation
of Solaris 10 Systems May Result in a System Panic
Under High TCP/IP Traffic
Product: Solaris 10 Operating System
Category: Security
Date Released: 13-Feb-2007
Date Closed: 13-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102796-1
-------------------------------------------------------------------
Sun Alert ID: 102799 (RESOLVED)
Synopsis: svc.startd(1M) May Core Dump While Removing a
Service, Causing patchrm(1M) to Terminate and Leave
the System Unbootable
Product: Solaris 10 Operating System
Category: Availability
Date Released: 12-Feb-2007
Date Closed: 12-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102799-1
-------------------------------------------------------------------
Sun Alert ID: 102800
Synopsis: Security Vulnerabilities in Mozilla 1.7 for Solaris
8, 9 and 10
Product: Mozilla v1.7, Solaris 9 Operating System, Solaris
10 Operating System, Solaris 8 Operating System
Category: Security
Date Released: 12-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102800-1
-------------------------------------------------------------------
Sun Alert ID: 102801
Synopsis: Certain HBA Cards in PCI-E Slot on Sun Fire
T2000(+) are Intermittently Not Recognized by OBP
During Boot
Product: Sun Fire T2000
Category: Availability, Availability
Date Released: 13-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102801-1
(before accessing this Sun Alert document please login to a SunSolve Online Account with a Sun Spectrum Support Contract at http://sunsolve.sun.com -> "Login")
-------------------------------------------------------------------
Sun Alert ID: 102802 (RESOLVED)
Synopsis: Security Vulnerability in the in.telnetd(1M) Daemon
May Allow Unauthorized Remote Users to Gain Access
to a Solaris Host
Product: Solaris 10 Operating System
Category: Security
Date Released: 12-Feb-2007, 13-Feb-2007
Date Closed: 13-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102802-1
-------------------------------------------------------------------
Sun Alert ID: 102803
Synopsis: Multiple Integer Overflow Vulnerabilities in the X
Font Server (xfs(1)) and the X Render and DBE
Extensions
Product: Solaris 9 Operating System, Solaris 10 Operating
System, Solaris 8 Operating System
Category: Security
Date Released: 13-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102803-1
-------------------------------------------------------------------
Updated Sun Alert Notifications
-------------------------------------------------------------------
(Total Updated: 6)
Sun Alert ID: 102546 (RESOLVED)
Synopsis: Sun Cluster on Solaris 10 Using Solaris Volume
Manager (SVM) Metasets May Fail to Fail-Over the
SVM Metasets
Product: Sun Cluster 3.1, Solaris Cluster 3.2
Category: Availability
Date Released: 01-Aug-2006, 13-Feb-2007
Date Closed: 13-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102546-1
-------------------------------------------------------------------
Sun Alert ID: 102551 (RESOLVED)
Synopsis: Solaris 10 System Panics May be Seen Under High
TCP/IP Stress Due to Race Conditions While Closing
TCP Instances
Product: Solaris 10 Operating System
Category: Availability
Date Released: 09-Aug-2006, 13-Feb-2007
Date Closed: 13-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102551-1
-------------------------------------------------------------------
Sun Alert ID: 102554 (RESOLVED)
Synopsis: On Solaris 10 Possible System Panics with a "Bad
Trap" from the drain_squeue() Function Under High
Stress
Product: Solaris 10 Operating System
Category: Availability
Date Released: 09-Aug-2006, 13-Feb-2007
Date Closed: 13-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102554-1
-------------------------------------------------------------------
Sun Alert ID: 102686 (RESOLVED)
Synopsis: Security Vulnerability in RSA Signature
Verification Affects Java 2 Platform, Standard
Edition
Product: Java 2 Platform, Standard Edition
Category: Security
Date Released: 15-Nov-2006, 15-Feb-2007
Date Closed: 15-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102686-1
-------------------------------------------------------------------
Sun Alert ID: 102771 (RESOLVED)
Synopsis: Missing Symbol in Font Library May Cause X Font
Server to Terminate Unexpectedly
Product: Solaris 9 Operating System, Solaris 8 Operating
System
Category: Availability
Date Released: 10-Jan-2007, 13-Feb-2007
Date Closed: 13-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102771-1
-------------------------------------------------------------------
Sun Alert ID: 102802 (RESOLVED)
Synopsis: Security Vulnerability in the in.telnetd(1M) Daemon
May Allow Unauthorized Remote Users to Gain Access
to a Solaris Host
Product: Solaris 10 Operating System
Category: Security
Date Released: 12-Feb-2007, 13-Feb-2007
Date Closed: 13-Feb-2007
To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102802-1
------------------------------------------------------------------
Additional Sun Alert Information
------------------------------------------------------------------
* Accessing Sun Alert Notifications
Sun Alert Notifications are accessed on http://sun.com/sunsolve under SunSolve Collections, Advanced Search, Browse Documents or Security Sun Alerts
* Sun Alert Patch Report
http://sun.com/sunsolve/sunalert_patches.html
This is a comprehensive report of patches mentioned in the Resolution section of Sun Alert documents and is available from SunSolve on the Patch Portal page. It is updated daily and organized by product.
-------------------------------------------------------------------
*IMPORTANT UPDATE* Changes to Solaris 8 and 9 Patch Access on SunSolve
-------------------------------------------------------------------
Beginning March 31, 2007, Sun is changing the way users will access Solaris 8 and 9 Software Updates (patches) to be consistent with the way users access Solaris 10 Software Updates.
Users will still be required to have a Sun Online Account and accept a Software License Agreement in order to access any Software Updates, but in addition users will be required to purchase a Solaris Subscription or Sun System Service Plan in order to access Solaris 8 and 9 Software Updates.
No Solaris Subscription or Sun System Service Plan will be required for security patches and device drivers, which will remain available without charge.
For more information, go to:
http://sunsolve.sun.com/search/document.do?assetkey=1-9-83061-1
For questions, contact: patchpolicy@sun.com
******************************************************************
Thanks for tuning in to the Sun Alert Weekly Summary Report!
Best regards,
Sun Alert Program Office
Sun Microsystems, Inc.
ALSO ON SUN.COM --------------------------------------------------
My Sun Connection: http://sun.com/mysunconnection
Products & Services: http://sun.com/products
Business & Industry Solutions: http://sun.com/solutions
Support & Training: http://sun.com/supportraining/
Downloads: http://sun.com/download
Documentation: http://sun.com/documentation
Research: http://sun.com/research
News: http://sun.com/news
Sun[sm] Store: http://sun.com/store
Resources for
* Developers: http://sun.com/developers
* System Admins: http://sun.com/bigadmin
* Partners: http://sun.com/partners
* Executives: http://sun.com/executives
* Investors: http://sun.com/investors
------------------------------------------------------------------
Copyright 2007 Sun Microsystems, Inc. All rights reserved.
Sun, Sun Microsystems, the Sun Logo, My Sun, iForce, Sun Fire, and Sun StorEdge are trademarks or registered trademarks of Sun Microsystems, Inc.
in the United States and other countries. All SPARC trademarks are used under license and are trademarks or registered trademarks of SPARC International, Inc. in the United States and other countries. Products bearing SPARC trademarks are based upon an architecture developed by Sun Microsystems, Inc.
:::::::::::::::::::::: We make the net work ::::::::::::::::::::::
______________________________________________________________________________
CPNI values your feedback.
1. Which of the following most reflects the value of the advisory to you?
(Place an 'X' next to your choice)
Very useful:__ Useful:__ Not useful:__
2. If you did not find it useful, why not?
3. Any other comments? How could we improve our advisories?
Thank you for your contribution.
______________________________________________________________________________
CPNI wishes to acknowledge the contributions of Sun for the information contained in this advisory.
______________________________________________________________________________