Security fix for VERITAS Cluster Server 4.0 (all versions) on Red Hat Enterprise Linux 3.0 (i686) - Symantec Security Advisory SYM05-023
Details:
This patch resolves a buffer overflow vulnerability in VERITAS Cluster Server 4.0 on Red Hat Enterprise Linux (RHEL) 3.0 for the i686 architecture.
This patch can be applied to 4.0 MP2 only. All other 4.0 versions must first be upgraded to MP2:
http://support.veritas.com/docs/278954 All releases of VERITAS Cluster Server 4.0 for RHEL 3.0 are affected and should be upgraded to MP2 and this patch applied. For further information on this vulnerability refer to
http://support.veritas.com/docs/279870 , which also contains links to patches for other platforms and versions.
This patch also contains a number of fixes for incidents not related to security (see below).
Refer to the information included in the patch file for installation instructions
Download Now - 22348 K
File Name: RHEL30i686_VCS4.0MP2+i18n-secfix-e418977a.tar_279952.gz
File Type: Patch
Click Below to Browse the FTP files by Product:
ftp.support.veritas.com/pub/support/products
Supplemental Material:| System: Ref.# | Description |
| ETrack: 414330 | Localization changes to VRTSvcs. |
| ETrack: 415105 | When online resource faults, notification not sent. |
| ETrack: 322217 | Removed unnecessary call from hacf. |
| ETrack: 426545 | Add engine check for username password length. |
| ETrack: 426548 | Packaging changes to remove root suid in some binaries. |
| ETrack: 423031 | VCS fails to bring parent group online after child group fails. |
| ETrack: 424476 | Unexpected cancellation of service threads. |
Products Applied:
Cluster Server for UNIX 4.0 MP1 (Linux), 4.0 MP2 (Linux)
Subjects:
Cluster Server for UNIX
Application: Patches
Linux
Applications: Patches
Languages:
English (US)
Operating Systems:
LinuxRHEL 3.0 (AS, ES, WS)
THE INFORMATION PROVIDED IN THE SYMANTEC SOFTWARE KNOWLEDGE BASE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. SYMANTEC SOFTWARE DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT SHALL SYMANTEC SOFTWARE OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES,EVEN IF SYMANTEC SOFTWARE OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.