I don't know if the following patches are available from Sun without
a support contract, but they fix the problem lb is describing:
for Solaris 2.5 SPARC: 103291-02
for Solaris 2.5.1 SPARC: 103738-04 (fix was actually made in 103738-01)
x86: 103739-05 (fix was actually made in 103739-01)
The actual Sun bug IDs this was reported under were 1249320 and 1245196.
According to the bug reports, only 2.5.x are affected (although I haven't
verified this). My 2.5 system with the patch applied doesn't appear to be
vulnerable.
Hope this helps....
- -Chris
+----------------------------------------------------------------------+
| Christopher Wilson chris.wilson@harris.com |
| Harris Corporation +-----------------------------+ |
| 1025 W Nasa Blvd, MS 75 For PGP public key, finger |
| Melbourne, FL 32919 cwilson@lurch.corp.harris.com |
+----------------------------------------------------------------------+
-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
iQB1AwUBNEzn/fwnuQEQYhQZAQFAoAL+PQ+3KqfAB4aObeBWhTqQpXIb1YKaTD0N
z/ZShsBiTpmy1rdch/jy8sakJXpwg60OPf3Q6h+YDCnLAo5uo199o3d1MoPwqxvC
/CMswscyg9qqFtdGg1vtDeV+m+75w2Pr
=PmwS
-----END PGP SIGNATURE-----