On Thu, 29 May 2008, James Cornell wrote:

> Hi Bob.  I tried on a fresh install of U5 and it works, or is the patch for 
> U5 cause I see quite a few from smpatch.

I am still running U4 here, but this would be a patch to U5 since it 
is recent (May/22/2008).  The x86 patch ID is 126134-03 and the SPARC 
patch ID is 126133.

Problem Description:

6504798 ssh fails for users when ngroups_max=32 
6684003 fix CVE-2008-1483 in SunSSH

(from 126134-02)

"This patch revision accumulates generic patch 127715-03 into Solaris 
Update S10U5 release.

Here is a link to a description of CVE-2008-1483:

   http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1483

Nowhere does the patch description say that it entirely disables 'ssh 
-X' but that seems to be the case.  The client requests the X11 
session and the server silently ignores it.

Bob
======================================
Bob Friesenhahn
bfriesen at simple.dallas.tx.us, http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/


Reply via email to