SUMMARY: What happened to CDE overflow patch for Tru64 v4.0g?

From: Phil Farrell (farrell@pangea.Stanford.EDU)
Date: Tue Sep 02 2003 - 18:56:23 EDT


Hi Managers,

Original query is appended.

I got replies from Dr. Thomas Blinn and Bob Vickers. The original
patch did indeed have installation problems, and that is probably why
it was withdrawn. Meanwhile, I just got the notice of a new
consolidated patch kit #4 for Tru64 v4.0g, so hopefully the missing
patch has been incorporated therein.

-Phil Farrell

---------- Forwarded message ----------
Date: Thu, 28 Aug 2003 09:56:19 -0700 (PDT)
From: Phil Farrell <farrell@pangea.Stanford.EDU>
To: tru64-unix-managers@ornl.gov
Followup-To: poster
Subject: What happened to CDE overflow patch for Tru64 v4.0g?

Hi Managers,

Back in May, I got a UNIX patch digest from HP describing a
security patch for the CDE buffer overflow problem. I was
too busy to deal with it then, and just yesterday wanted to
get back to installing it. When I went to HP's ftp site,
the patch was gone for Tru64 versions 4.0f and 4.0g. It
was still there for versions 5.1a and 5.1b. I run 4.0g, so
I was a bit disconcerted by this. Anyone know what happened
to this patch? Was it deliberately withdrawn? Or is this
an accident? If anyone has installed this patch on their
4.0g machine with no problems and still has the tarball, can
you let me have a copy? Thanks.

-Phil Farrell, Computer Systems Manager
Stanford University School of Earth Sciences
farrell@pangea.stanford.edu

Here's the first part of the patch digest referencing the patch
name and location. It is no longer at that location, nor
anywhere else that I could find on HPs web site.

UNIX Digest for Wednesday, May 28, 2003.

1. Potential CDE Buffer Overflows (PK3)
2. Potential CDE Buffer Overflows (PK4)
3. Potential CDE Buffer Overflows (PK6)
4. Potential CDE Buffer Overflows

----------------------------------------------------------------------

Subject: Potential CDE Buffer Overflows (PK3)
From: system PRIVILEGED account <root@stage1.cxo.cpqcorp.net>
Date: Wed, 28 May 2003 01:30:08 -0600 (MDT)
X-Message-Number: 1

*******************************************************************************
* *
* This is a newly released patch... *
* *
* Online links can be found at *
* http://ftp.support.compaq.com/patches/public/unix/v4.0g/t64v40gb17-c0029600-18524-es-20030506.README
*******************************************************************************



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:49:34 EDT