ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Application development Toolkit

CERT warns on Sun server flaw

Patrick Gray ZDNet Australia

Published: 13 Dec 2002 10:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Users of Sun's RaQ 4 Server appliance have been warned in the latest CERT advisory of a serious vulnerability affecting the units.

"A remotely exploitable vulnerability has been discovered in Sun Cobalt RaQ 4 Server Appliances... may allow remote attackers to execute arbitrary code with superuser privileges," the CERT advisory said.

Ironically the vulnerability only affects Raq 4 units with Sun's Security Hardening Patch (SHP) installed on them.

Perhaps of most concern is the fact that a technique for exploiting this vulnerability has already been developed, and the relevant code has been made available to the public. It's been available from the SecuriTeam Web site since Saturday.

"An exploit is publicly available and may be circulating," the advisory said.

The CERT Advisory contains a link to Sun's instructions on how to remove the SHP; however, the link retrieves an "error opening document" message. The link to the "SHP Removal patch" is working.

CERT had made their "vulnerability notes" about the RaQ 4 unit public as far back as the 5th of December, however the full-blown advisory was not published until yesterday.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
34 out of 74 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Lotus Notes / Domino Developer - Global Client - Urgent

Huxley Associates reputable client based in Paddington, Central London have the requirement for 2x Lotus Notes Developers to start immediately for ...

2nd/ 3rd Line Support - Windows Server / OS Lotus Notes - Bedford

Focused on the support & administration of a windows & lotus notes based infrastructure, the following skills are necessary: Windows Servers ...

JUNIOR JAVA DEVELOPER

Error! HTML/CSS mark up - Struts action classes Error! Great sense of humour and attitude Error! JUNIOR JAVA DEVELOPER NET-A-PORTER is an established ...

Discussions

pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments

Featured Talkback

The fact is: Software developers today are really designers and not coders. The reason that business anlaysts exist today to model solutions is because they understand the value of designing software before writing it. All too often developers create code that has little value because they do not understand that business classes interact with other classes within the confines of a working model or pattern.

By: 1000165269

Read full story:
Making sense of agile modelling