Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
    • Risk Management Delivery Group
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > July 2007 > 3299 - SUN Weekly Summary

July 2007

3299 - SUN Weekly Summary

ID: 3299
Date: 31 July 2007 13:02

Title: 3299 - SUN Weekly Summary
Abstract: The Sun(SM) Alert Weekly Summary Report, a newsletter that provides a weekly listing of newly released and updated Sun Alert Notifications
Vendors affected:Sun
Availability of fix: Available
Type of fix: Patch
Source: Sun
Reliability of source: Trusted

SUN(SM) ALERT WEEKLY SUMMARY REPORT

     Week of 22-Jul-2007 - 28-Jul-2007

Welcome to the Sun(SM) Alert Weekly Summary Report, the newsletter that provides you with a weekly listing of newly released and updated Sun Alert Notifications.  It is being distributed to inform you about critical hardware and software issues that could impact the availability, security, and data integrity of your computing environment.

==================================================================
ISSUE HIGHLIGHTS

* Newly Released Sun Alert Notifications

* Updated Sun Alert Notifications

* Additional Sun Alert Information

* Changes to Patch Access on SunSolve

==================================================================

-------------------------------------------------------------------
Newly Released Sun Alert Notifications
-------------------------------------------------------------------
(Total Released: 8)

Sun Alert ID:  102948 (RESOLVED)
Synopsis:      A Security Vulnerability in lbxproxy(1) may Allow
               Unauthorized Read Access to Files
Product:       Solaris 9 Operating System, Solaris 10 Operating
               System, Solaris 8 Operating System
Category:      Security
Date Released: 25-Jul-2007
Date Closed:   25-Jul-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102948-1

-------------------------------------------------------------------
Sun Alert ID:  103000
Synopsis:      JSP Source Code Exposure Issue on Windows Platform
               Affects Sun Java System Application Server
Product:       Sun Java System Application Server Platform Edition
               8.1 2005Q1, Sun Java System Application Server
               Enterprise Edition 8.2, Sun Java System Application
               Server Enterprise Edition 8.1 2005Q1, SJS
               Application Server PE 8.2
Category:      Security
Date Released: 24-Jul-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103000-1

-------------------------------------------------------------------
Sun Alert ID:  103011
Synopsis:      Security Vulnerability in Mozilla 1.7 May Allow
               Arbitrary JavaScript Commands to be Run
Product:       Mozilla v1.7
Category:      Security
Date Released: 24-Jul-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103011-1

-------------------------------------------------------------------
Sun Alert ID:  103013
Synopsis:      Solaris 9 libresolv or DHCP Patches May Cause
               "in.dhcpd" to Quit
Product:       Solaris 9 Operating System
Category:      Availability
Date Released: 23-Jul-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103013-1

-------------------------------------------------------------------
Sun Alert ID:  103014
Synopsis:      In Rare Cases, Small Appending Writes to Cluster
               Files May Result in Data Integrity Issues
Product:       Sun Cluster 3.1, Solaris Cluster 3.2
Category:      Data Loss, Availability
Date Released: 23-Jul-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103014-1

-------------------------------------------------------------------
Sun Alert ID:  103016
Synopsis:      Sun Fire 12K/15K/E20K/E25K Domains Running Solaris
               8 2/04 May Experience Bus Error When Using Dynamic
               Reconfiguration
Product:       Sun Fire 12K Server, Sun Fire E20K Server, Sun Fire
               15K Server, Sun Fire E25K Server
Category:      Availability
Date Released: 24-Jul-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103016-1
(before accessing this Sun Alert document please login to a SunSolve Online Account with a Sun Spectrum Support Contract at http://sunsolve.sun.com -> "Login")

-------------------------------------------------------------------
Sun Alert ID:  103017
Synopsis:      Sun Fire X4100/X4200 Servers with AMD8131 Chipset
               May Require New I/O Card Drivers to Address AMD
               "errata 62"
Product:       Sun Fire X4100 Server, Sun Fire X4200 Server
Category:      Availability
Date Released: 24-Jul-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103017-1
(before accessing this Sun Alert document please login to a SunSolve Online Account with a Sun Spectrum Support Contract at http://sunsolve.sun.com -> "Login")

-------------------------------------------------------------------
Sun Alert ID:  103018
Synopsis:      Security Vulnerability in Solaris 10 BIND:
               Susceptible to Cache Poisoning Attack
Product:       Solaris 10 Operating System
Category:      Security
Date Released: 25-Jul-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103018-1


-------------------------------------------------------------------
Updated Sun Alert Notifications
-------------------------------------------------------------------
(Total Updated: 4)

Sun Alert ID:  102785 (RESOLVED)
Synopsis:      Solaris 8, 9 and 10 Systems may Hang with Emulex
               HBA Hardware Error
Product:       Solaris 9 Operating System, Solaris 10 Operating
               System, Solaris 8 Operating System
Category:      Availability
Date Released: 07-Feb-2007, 26-Jul-2007
Date Closed:   26-Jul-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102785-1

-------------------------------------------------------------------
Sun Alert ID:  102886 (RESOLVED)
Synopsis:      Multiple vulnerabilities in libfreetype, Xsun(1)
               and Xorg(1)
Product:       Solaris 9 Operating System, Solaris 10 Operating
               System, Solaris 8 Operating System
Category:      Security
Date Released: 25-Apr-2007, 25-May-2007, 26-Jul-2007
Date Closed:   26-Jul-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1

-------------------------------------------------------------------
Sun Alert ID:  102888 (RESOLVED)
Synopsis:      Security Vulnerability in libX11 for Solaris
Product:       Solaris 9 Operating System, Solaris 10 Operating
               System, Solaris 8 Operating System
Category:      Security
Date Released: 24-Apr-2007, 25-Jul-2007
Date Closed:   25-Jul-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102888-1

-------------------------------------------------------------------
Sun Alert ID:  102944 (RESOLVED)
Synopsis:      StorageTek  5210/5220/5310/5320 NAS Tape Library
               with Multiple Drives Sharing the Same Target IDs
               May Lose Drive Visibility to the NDMP Backup Module
Product:       Sun StorageTek 5310 NAS Appliance, Sun StorageTek
               5320 NAS Appliance, Sun StorageTek 5220 NAS
               Appliance, Sun StorageTek 5210 NAS Appliance
Category:      Availability
Date Released: 01-Jun-2007, 24-Jul-2007
Date Closed:   24-Jul-2007

To view this Sun Alert document please go to the following URL:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102944-1

------------------------------------------------------------------
Additional Sun Alert Information
------------------------------------------------------------------

* Accessing Sun Alert Notifications

Sun Alert Notifications are accessed on http://sun.com/sunsolve under SunSolve Collections, Advanced Search, Browse Documents or Security Sun Alerts


* Sun Alert Patch Report

http://sun.com/sunsolve/sunalert_patches.html

This is a comprehensive report of patches mentioned in the Resolution section of Sun Alert documents and is available from SunSolve on the Patch Portal page. It is updated daily and organized by product.


-------------------------------------------------------------------
*IMPORTANT UPDATE* Changes to Solaris 8 and 9 Patch Access on SunSolve
-------------------------------------------------------------------

Beginning March 31, 2007, Sun is changing the way users will access Solaris 8 and 9 Software Updates (patches) to be consistent with the way users access Solaris 10 Software Updates.

Users will still be required to have a Sun Online Account and accept a Software License Agreement in order to access any Software Updates, but in addition users will be required to purchase a Solaris Subscription or Sun System Service Plan in order to access Solaris 8 and 9 Software Updates.

No Solaris Subscription or Sun System Service Plan will be required for security patches and device drivers, which will remain available without charge.

For more information, go to:

   http://sunsolve.sun.com/search/document.do?assetkey=1-9-83061-1

For questions, contact: patchpolicy@sun.com


******************************************************************

Thanks for tuning in to the Sun Alert Weekly Summary Report!

Best regards,
Sun Alert Program Office
Sun Microsystems, Inc.


ALSO ON SUN.COM --------------------------------------------------
My Sun Connection:             http://sun.com/mysunconnection
Products & Services:           http://sun.com/products
Business & Industry Solutions: http://sun.com/solutions
Support & Training:            http://sun.com/supportraining/
Downloads:                     http://sun.com/download
Documentation:                 http://sun.com/documentation
Research:                      http://sun.com/research
News:                          http://sun.com/news
Sun[sm] Store:                 http://sun.com/store

Resources for
* Developers:                  http://sun.com/developers
* System Admins:               http://sun.com/bigadmin
* Partners:                    http://sun.com/partners
* Executives:                  http://sun.com/executives
* Investors:                   http://sun.com/investors
------------------------------------------------------------------

Copyright 2007 Sun Microsystems, Inc. All rights reserved.

Sun, Sun Microsystems, the Sun Logo, My Sun, iForce, Sun Fire, and Sun StorEdge are trademarks or registered trademarks of Sun Microsystems, Inc. in the United States and other countries. All SPARC trademarks are used under license and are trademarks or registered trademarks of SPARC International, Inc. in the United States and other countries. Products bearing SPARC trademarks are based upon an architecture developed by Sun Microsystems, Inc.


 

This advisory contains information released by the original author. Some of the information may have changed since it was released. If the issue affects you, it may be prudent to retrieve the advisory from the site of the original source to ensure that you receive the most current information concerning that problem. Reference to any specific commercial product, process, or service by trade name, trademark manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favouring by CPNI.

The views and opinions of authors expressed within this notice shall not be used for advertising or product endorsement purposes. CPNI shall not accept responsibility for any errors or omissions contained within this advisory. In particular, they shall not be liable for any loss or damage whatsoever, arising from or in connection with the usage of information contained within this advisory.

CSIRTUK is a member of the Forum of Incident Response and Security Teams (FIRST) and has contacts with other international Incident Response Teams (IRTs) in order to foster cooperation and coordination in incident prevention, to prompt rapid reaction to incidents, and to promote information sharing amongst its members and the community at large.

  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |