Patches & Updates
Deploy and monitor updates to all of your systems through Sun from anywhere you have an Internet connection.
Start today with Knowledge-based software update services for Solaris and Linux.
Please review changes to Patch Access.
Patches:
Download Patch (37984 bytes): HTTP 
Download Signed Patch (41243 bytes): HTTP 
Signed Patch Documentation  Patch Finder

SunOS 5.7_x86: /usr/sbin/in.ftpd Patch


Status: RELEASED
Patch Id: 110647-06
Summary: SunOS 5.7_x86: /usr/sbin/in.ftpd Patch
Date:  Dec/20/2004
Installation Requirements:
None
Solaris Release: 7_x86
Sun OS Release: 5.7_x86
Unbundled Product: 
Unbundled Release: 
Xref: This patch available for SPARC as patch 110646
Topic: 
SunOS 5.7_x86: /usr/sbin/in.ftpd Patch
Relevant Architecture: i386
BugId's fixed with this patch:

4139895 4244544 4436988 4445755 4446600 4451524 4452705 4714534 4758151 5108531

Changes incorporated in this version:

5108531

Patches accumulated and obsoleted by this patch:

Patches which conflict with this patch: 

Required Patches:

Obsoleted by:
 
Files Included in this Patch: 
/usr/sbin/in.ftpd
Problem Description: 
5108531 CVE-1999-0079 multiple PASV allow multiple port bound causes running out of port
 
(from 110647-05)
 
4758151 /usr/sbin/in.ftpd does not properly implement PAM
 
(from 110647-04)
 
4714534 FTP server connect retry DOS vulnerability
 
(from 110647-03)
 
4244544 in.ftpd doesn't preserve S_ISGID bit on directories
 
(from 110647-02)
 
4436988 security: Globbing problem in in.ftpd
4446600 ftpd memory leaks
4445755 ftpd glob can still use a lot of memory and CPU
4451524 in.ftpd cores
4452705 GAVSIZ definition needs to stay in glob.c
 
(from 110647-01)
 
4139895 in.ftpd can be fooled to connect to a reserved port
Revision History: 

110647-03 110647-05 110647-04 110647-02

Patch Installation Instructions: 
--------------------------------
 
For Solaris 2.0-2.6 releases, refer to the Install.info file and/or
the README within the patch for instructions on using the generic
'installpatch' and 'backoutpatch' scripts provided with each patch.
 
For Solaris 7-9 releases, refer to the man pages for instructions
on using 'patchadd' and 'patchrm' scripts provided with Solaris.
Any other special or non-generic installation instructions should be
described below as special instructions.  The following example
installs a patch to a standalone machine:
 
       example# patchadd /var/spool/patch/104945-02
 
The following example removes a patch from a standalone system:
 
       example# patchrm 104945-02
 
For additional examples please see the appropriate man pages.
Special Install Instructions: 
-----------------------------
None.

README -- Last modified date:  Monday, December 20, 2004

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 110647-06
Article Type : Patch Descriptions
Last reviewed : 2004-12-20
Audience : PUBLIC
Keywords : security in.ftpd reserved port
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article