[comp.unix.ultrix] Does 3.1 fix security prob. in 3.0?

art@dinorah.wustl.edu (Arthur B. Smith) (08/14/89)

Several months ago, when Ultrix 3.0 was the latest greatest thing, DEC
sent out a "Mandatory Workaround" to avoid problems from chfn, chsh
and domainname.  Now we have Ultrix 3.1 (which replaced chfn and chsh,
but not domainname).  I called DEC Software Support in Atlanta this
morning, and they not only didn't know if 3.1 fixed these bugs, they
didn't know anything at all about the bugs in 3.0....!  They have the
call out to some other part of the company to find out about this, but
expect it to take several days.  Does anyone out there in Netland know
whether Ultrix 3.1 fixed any or all of these problems?  

    	-art smith  (art@dinorah.wustl.edu, ...!uunet!wucs1!dinorah!art)

"DEC -- not only doesn't their right hand know what the left hand is
doing, it is surprised to find out there IS a left hand."   -me

Usual disclaimers....

grr@cbmvax.UUCP (George Robbins) (08/19/89)

In article <940@dinorah.wustl.edu> art@dinorah.wustl.edu (Arthur B. Smith) writes:
> 
> Several months ago, when Ultrix 3.0 was the latest greatest thing, DEC
> sent out a "Mandatory Workaround" to avoid problems from chfn, chsh
> and domainname.  Now we have Ultrix 3.1 (which replaced chfn and chsh,
> but not domainname).
...
> Does anyone out there in Netland know
> whether Ultrix 3.1 fixed any or all of these problems?  

My understanding is that the known class of bugs represented by chfn/chsh
did get fixed.  I'm not familar with the domainname varient.  The sendmail/
debug thing wasn't a problem with Ultrix, since debug was disabled...

I've never recieved any of the "security notes" from DEC, though I am the
one who ends up with all the tapes and non-billing paperwork.  I wonder who
DEC thinks is supposed to be receiving these at my site?

-- 
George Robbins - now working for,	uucp: {uunet|pyramid|rutgers}!cbmvax!grr
but no way officially representing	arpa: cbmvax!grr@uunet.uu.net
Commodore, Engineering Department	fone: 215-431-9255 (only by moonlite)