HP Tru64 UNIX and TruCluster Server Version 5.1B-6 Patch Summary and Release Notes

PATCH 28085.00
OSFX11540
This fix addresses a X-Motif list widget problem while selecting an item from a long list.
PATCH 28102.00
OSFCDSABASE540
Fixes a problem with CDSA configuration where mod_install program can core dump.
PATCH 28107.00
OSFLDPAUTH540
Fixes ldapcd daemon to service the requests faster after failover from primary Active
Directory to Backup Active Directory.
Fixes the locale problem in ldapcd daemon script.
PATCH 28113.00
OSFSSHBASE540
Corrects a potential security vulnerability that has been identified with SSH running on the
HP Tru64 UNIX Operating System. Vulnerability could be exploited to allow remote
unauthorized access to sensitive information.
Updates the SSH client to use protocol version 2.
Fixes wildcard matching and globing in scp2/sftp2 ls -l command.
A potential security vulnerability has been identified in the SFTP server (sftp-server)
component of SSH 3.2.0 and earlier running on HP Tru64 UNIX versions 5.1B-3 and 5.1B-4.
The vulnerability could be exploited remotely to allow an authorized remote attacker to
execute arbitrary code or cause a denial of service (DoS).
Patch 27001.00
OSFACCT540
Corrects the action of the dodisk command to skip the commented file systems contained
in the /etc/fstab file.
Fixes acctcom to exit with proper error message when used with invalid user ID and group
ID.
Causes the file protections of /var/adm/pacct and ownership of /var/adm/wtmp to act as
expected by the accounting utilities.
Fixes the fwtmp command so it does not display invalid (negative) PIDs when the number
of decimal digits of PID value exceeds 5.
Corrects a potential security vulnerability where, under certain circumstances, system
integrity may be compromised. This may be in the form of improper file or privilege
management.
Corrects an error in the script in lastlogin.sh.
Makes start up scripts in /sbin/init.d world readable.
Corrects the following problems found in accounting commands:
— Resolves the differences in the CPU time and connect time found during the conversion
of accounting reports from ASCII format to binary and again back to ASCII.
— Resolves the differences in CPU time found in the output of the acctcom and acctmerg
commands for the same input file.
— Fixes the way accounting files are referenced using CDSLs.
— Corrects the display of the header from acctcom when accounting is first started.
— Corrects an error message during execution of the runacct command.
70 Tru64 UNIX Patches