Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
    • Risk Management Delivery Group
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > May 2007 > SUN(SM) ALERT WEEKLY SUMMARY REPORT - Week of 29-Apr-2007 - 05-May-2007

May 2007

SUN(SM) ALERT WEEKLY SUMMARY REPORT - Week of 29-Apr-2007 - 05-May-2007

ID: 129
Ref: 071/2007
Date: 09 May 2007:11:34:16
Version: 1

Title: SUN(SM) ALERT WEEKLY SUMMARY REPORT - Week of 29-Apr-2007 - 05-May-2007
Abstract: Sun Alert Weekly Summary Report
Vendors affected: Sun
Operating systems affected: Sun

Welcome to the Sun(SM) Alert Weekly Summary Report, the newsletter that provides you with a weekly listing of newly released and updated Sun Alert Notifications. It is being distributed to inform you about critical hardware and software issues that could impact the availability, security, and data integrity of your computing environment.

==================================================================
ISSUE HIGHLIGHTS

* Newly Released Sun Alert Notifications

* Updated Sun Alert Notifications

* Additional Sun Alert Information

* Changes to Patch Access on SunSolve

==================================================================

-------------------------------------------------------------------
Newly Released Sun Alert Notifications
-------------------------------------------------------------------
(Total Released: 5)

Sun Alert ID: 102881 (RESOLVED)
Synopsis: Security Vulnerability With Java Web Start Related
to Incorrect Use of System Classes
Product: Java 2 Platform, Standard Edition
Category: Security
Date Released: 30-Apr-2007
Date Closed: 30-Apr-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102881-1

-------------------------------------------------------------------
Sun Alert ID: 102895 (RESOLVED)
Synopsis: Security Vulnerability in Sun Java System Directory
Server May Cause Denial of Service (DoS)
Product: Sun Java System Directory Server 5.2, Sun Java
System Directory Server Enterprise Edition, Sun ONE
Directory Server 5.1
Category: Security
Date Released: 01-May-2007
Date Closed: 01-May-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102895-1

-------------------------------------------------------------------
Sun Alert ID: 102900 (RESOLVED)
Synopsis: Solaris 9 Systems With Solaris Auditing (BSM)
Enabled may Panic if Certain Audit Classes are
Being Audited
Product: Solaris 9 Operating System
Category: Security, Availability
Date Released: 01-May-2007
Date Closed: 01-May-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102900-1

-------------------------------------------------------------------
Sun Alert ID: 102901
Synopsis: Xorg(1) Contains a Denial of Service Within the X
Render Extension's Trapezoid Rendering
Product: Solaris 9 Operating System, Solaris 10 Operating
System
Category: Security
Date Released: 03-May-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102901-1

-------------------------------------------------------------------
Sun Alert ID: 102904
Synopsis: Changing the Array Volume-to-LUN Mappings May Cause
Array Controllers to Initiate a Boot-Loop
Product: Sun StorageTek 5310 NAS Appliance, Sun StorageTek
5320 NAS Appliance, Sun StorageTek 6130 Array, Sun
StorageTek 6140 Array, Sun StorageTek 6540 Array
Category: Availability
Date Released: 03-May-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102904-1
(before accessing this Sun Alert document please login to a SunSolve Online Account with a Sun Spectrum Support Contract at http://sunsolve.sun.com -> "Login")


-------------------------------------------------------------------
Updated Sun Alert Notifications
-------------------------------------------------------------------
(Total Updated: 5)

Sun Alert ID: 102847 (RESOLVED)
Synopsis: Multiple Security Vulnerabilities in Adobe Reader
May Lead to Execution of Arbitrary Code
Product: Solaris 10 Operating System
Category: Security
Date Released: 14-Mar-2007, 30-Apr-2007
Date Closed: 30-Apr-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1

-------------------------------------------------------------------
Sun Alert ID: 102853 (RESOLVED)
Synopsis: The Directory Server ("ns-slapd") May Exit
Unexpectedly When Handling Certain Queries
Product: Sun Java System Directory Server 5.1 Service Pack
3, Sun Java System Directory Server 5.2, Sun Java
System Directory Server Enterprise Edition
Category: Security
Date Released: 23-Mar-2007, 03-May-2007
Date Closed: 03-May-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102853-1

-------------------------------------------------------------------
Sun Alert ID: 102860 (RESOLVED)
Synopsis: Solaris 10 Systems May Panic With Message
"tte_remap"
Product: Solaris 10 Operating System
Category: Availability
Date Released: 29-Mar-2007, 02-May-2007
Date Closed: 02-May-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102860-1

-------------------------------------------------------------------
Sun Alert ID: 102877 (RESOLVED)
Synopsis: Sun SPARC Enterprise M4000/5000/8000/9000 Servers
May Panic Due to Wrong sTLB Setting
Product: Solaris 10 Operating System
Category: Availability
Date Released: 17-Apr-2007, 02-May-2007
Date Closed: 02-May-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102877-1

-------------------------------------------------------------------
Sun Alert ID: 102896 (RESOLVED)
Synopsis: Directory Server May Hang Due to a Memory Leak in
the Network Security Services (NSS) Software
Product: Sun Java System Directory Server 5.2, Sun Java
System Directory Server Enterprise Edition
Category: Security
Date Released: 27-Apr-2007, 03-May-2007
Date Closed: 03-May-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102896-1

------------------------------------------------------------------
Additional Sun Alert Information
------------------------------------------------------------------

* Accessing Sun Alert Notifications

Sun Alert Notifications are accessed on http://sun.com/sunsolve under SunSolve Collections, Advanced Search, Browse Documents or Security Sun Alerts


* Sun Alert Patch Report

http://sun.com/sunsolve/sunalert_patches.html

This is a comprehensive report of patches mentioned in the Resolution section of Sun Alert documents and is available from SunSolve on the Patch Portal page. It is updated daily and organized by product.


-------------------------------------------------------------------
*IMPORTANT UPDATE* Changes to Solaris 8 and 9 Patch Access on SunSolve
-------------------------------------------------------------------

Beginning March 31, 2007, Sun is changing the way users will access Solaris 8 and 9 Software Updates (patches) to be consistent with the way users access Solaris 10 Software Updates.

Users will still be required to have a Sun Online Account and accept a Software License Agreement in order to access any Software Updates, but in addition users will be required to purchase a Solaris Subscription or Sun System Service Plan in order to access Solaris 8 and 9 Software Updates.

No Solaris Subscription or Sun System Service Plan will be required for security patches and device drivers, which will remain available without charge.

For more information, go to:

http://sunsolve.sun.com/search/document.do?assetkey=1-9-83061-1

For questions, contact: patchpolicy@sun.com


******************************************************************

Thanks for tuning in to the Sun Alert Weekly Summary Report!

Best regards,
Sun Alert Program Office
Sun Microsystems, Inc.


ALSO ON SUN.COM --------------------------------------------------
My Sun Connection: http://sun.com/mysunconnection
Products & Services: http://sun.com/products
Business & Industry Solutions: http://sun.com/solutions
Support & Training: http://sun.com/supportraining/
Downloads: http://sun.com/download
Documentation: http://sun.com/documentation
Research: http://sun.com/research
News: http://sun.com/news
Sun[sm] Store: http://sun.com/store

Resources for
* Developers: http://sun.com/developers
* System Admins: http://sun.com/bigadmin
* Partners: http://sun.com/partners
* Executives: http://sun.com/executives
* Investors: http://sun.com/investors
------------------------------------------------------------------

Copyright 2007 Sun Microsystems, Inc. All rights reserved.

Sun, Sun Microsystems, the Sun Logo, My Sun, iForce, Sun Fire, and Sun StorEdge are trademarks or registered trademarks of Sun Microsystems, Inc. in the United States and other countries. All SPARC trademarks are used under license and are trademarks or registered trademarks of SPARC International, Inc. in the United States and other countries. Products bearing SPARC trademarks are based upon an architecture developed by Sun Microsystems, Inc.

:::::::::::::::::::::: We make the net work ::::::::::::::::::::::
  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |