This page is for my own personal use with my Cobalt RaQ4. This content on this page is NOT mine. It all belongs to Sun Microsystems, Inc.

Downloads should be applied from the bottom of the page to the top, as they must be applied in chronlogical order. Application of these patches in improper order will likely result in problems with the Sun Cobalt™ product.


Note: For all previous updates, please see http://ftp.cobalt.sun.com

The md5sums listed below are for the unzipped ISO image files and not for the .gz files


Mutt Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16706.pkg Posted:April 12, 2004
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 418,941

This update fixes security vulnerabilities with mutt.

Pre-Requisites:
None.

Reboot Required: No

MD5 Check Sum: 4a1b391bc789cd469fbcb20f1fe2eb55


ProFTPD Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16717.pkg Posted:April 19, 2004
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 838,029

This update addresses a buffer overflow vulnerability with ProFTPD.

Pre-Requisites:
RaQ4-All-Security-2.0.1-15823.pkg

Reboot Required: No

MD5 Check Sum: d47fcf99b19603d5096a18e63d3f5c72


Pine Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16612.pkg Posted:March 17, 2004
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 1,861,438

This patch fixes security vulnerabilities in Pine.

Pre-Requisites:
None.

Reboot Required: No

MD5 Check Sum: 5173af407a7acffbd47d300d48279266


Fileutils Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16648.pkg Posted:February 10, 2004
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 638,880

This updates address a remote denial of services vulnerability in the ls program, a utility that is part of the fileutils package.

Pre-Requisites:
None.

Reboot Required: No

MD5 Check Sum: 0160b0e292073272a0062e3ed64c8e1d


Rsync Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16675.pkg Posted:February 10, 2004
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 123,565

This update addresses a heap overflow vulnerability in rsync, is a program for sychronizing files over the network.

Pre-Requisites:
None.

Reboot Required: No

MD5 Check Sum: 982e0aee16bfef2c7bf6941fd82a2134


BIND Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16662.pkg Posted:January 16, 2004
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 3,126,152

This update addresses a vulnerability in BIND, that could allow an attacker to conduct cache poisoning attacks on the name servers by convincing the servers to retain invalid negative responses.

For more information, see: CAN-2003-0914

Pre-Requisites:
RaQ4-All-Security-2.0.1-16311.pkg

Reboot Required: No

MD5 Check Sum: 3ccc453abf220577299a29602147e8aa


Slocate Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16633.pkg Posted:January 16, 2004
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 30,057

This update addresses a vulnerability in slocate where the heap management structures could be corrupted possibly lead to an attacker gaining slocate group privileges.
for more information, see: CAN-2003-0848

Reboot Required: No

MD5 Check Sum: 7da97b57a3e721a506f95159337dc18e


Tcpdump Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16504.pkg Posted:January 16, 2004
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 260,171

This update adresses a vulnerability in tcpdump, where the privileges were not dropped corrextly at startup time. for more information, see: CAN-2003-0194

Pre-Requisites:
RaQ4-All-Security-2.0.1-14559.pkg

Reboot Required: No

MD5 Check Sum: 68c07c7d46673e2505ce769192557061


Bash Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16602.pkg Posted:December 19, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 232,034

This update addresses a vulnerability in the bash shell. Temporary files were created with insecure permissions, which could allow an attacker to launch a symlink attack to overwrite arbitrary files.
For more information, see: CAN-2000-1134

Reboot Required: No

MD5 Check Sum: 637eeb5554fd973769ca9c2904a24b8a


Sendmail Security Update 2.0.2

HTTP RaQ4-All-Security-2.0.2-16620.pkg Posted:December 05, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 860,843

This update addresses two vulnerabilities in Sendmail.

  • The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks. See: CAN-2003-0694
  • A potential buffer overflow in ruleset parsing. See: CAN-2003-0681

Version 2.0.1 ofthe patch did not preserve the configuration file correctly. This updated version (2.0.2) addresses this problem.

Pre-Requisites:
RaQ4-All-Security-2.0.1-16429.pkg

Reboot Required: No

MD5 Check Sum: bbe4af96f826c3476286fdd48ae3497f


Apache & mod_ssl Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16622.pkg Posted:December 05, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 2,802,708

This update addresses vulnerabilities discovered in Apache and mod_ssl.

  • Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences. See CAN-2003-0020
  • mod_ssl does not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite. See CAN-2003-0192

Pre-Requisites:
RaQ4-All-Security-2.0.1-16343.pkg

Reboot Required: Yes

MD5 Check Sum: 1395cdb3d48c76b598cbd79a43eeb8e3


NFS-Utils Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16571.pkg Posted:December 01, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 176,789

This update addresses a buffer overflow in nfs-utils that could be exploited by an attacker, causing a remote Denial of Service.
For more information, see CAN-2003-0252

Reboot Required: No

MD5 Check Sum: 3afb09c7032e5fcd94e5ee291c328d43


Sendmail Security Update 2.0.1 ***Replaced***

HTTP RaQ4-All-Security-2.0.1-16620.pkg Posted:October 05, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 860,822

This update addresses two vulnerabilities in Sendmail.

  • The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks. See: CAN-2003-0694
  • A potential buffer overflow in ruleset parsing. See: CAN-2003-0681

Pre-Requisites:
RaQ4-All-Security-2.0.1-16429.pkg

Reboot Required: No

MD5 Check Sum: ba1fc625005f7c9d84f2fb4cace2ae67


Imap Clients Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16505.pkg Posted:September 22, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 4,691,014

This update addresses multiple buffer overflow vulnerabilities discovered in various IMAP clients (Pine, Mutt, Imap).

Reboot Required: No

MD5 Check Sum: 8e61a1e9a313f87d269ceae03f33104d


BIND Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16311.pkg Posted:September 22, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 3,279,749

This update addresses multiple vulnerabilities discovered in the Berkeley Internet Name Domain Server (BIND).

Reboot Required: No

MD5 Check Sum: c26bbca1ac66a5b759b65afc4c783c31


Unzip Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16561.pkg Posted:September 04, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 131,889

Updated unzip packages resolve a vulnerability allowing arbitrary files to be overwritten. The original patch to fix this issue (16170) missed a case where the path component included a quoted slash. These updated packages contain a new patch that corrects this issue.

for more information, see: CAN-2003-0282

Reboot Required: No

MD5 Check Sum: 0768c2e8ebbbc2997026eac6cf15d989


Zlib Security Update 2.0.2

HTTP RaQ4-All-Security-2.0.1-16487.pkg Posted:July 07, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 99,995

This update addresses a buffer overflow vulnerability in the gzprintf function of the zlib compression package.

For mor information, see CAN-2003-0107

Reboot Required: No

MD5 Check Sum: 2bf5b46bc1027e4d787fab4529b529ca


Maximum Disk Space Update 2.0.1

HTTP RaQ4-All-System-2.0.1-16494.pkg Posted:May 28, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 2,275

This update addresses a problem when setting the maximum disk space for a virtual site to a value divisible by 10.

Reboot Required: No

MD5 Check Sum: 1cf0bfa6f15770a69b63ecf9a387eb6a


Kernel Update C37 2.0.1

HTTP RaQ4-All-Kernel-2.0.1-2.2.16C37-III-1-2.pkg Posted:May 19, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 4,205,939

This updated kernel fixes a vulnerability in ptrace that could allow local users to obtain full privileges. Remote exploitation of this hole is not possible. For more information see: CAN-2003-0127

This kernel also fixes a problem with the I2C driver where the locks were not IRQ safe. This could cause problems including the system reporting false fan failures, repeated raid syncs, and random reboots.

Reboot Required: Yes

MD5 Check Sum: a5b1f97c372cb5b517558e141792e3d9


Vim Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16358.pkg Posted:May 08, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 3,815,127

This update addresses a vulnerability found in the Vim editor, that could allow attackers to execute arbitrary commands using the libcall feature in modelines. For more information, see CAN-2002-1377

Reboot Required: No

MD5 Check Sum: 8b0f0b92200cff373028a338dca568e8


Apache & SSL Security 2.0.1

HTTP RaQ4-All-Security-2.0.1-16343.pkg Posted:May 08, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 2,831,977

This update addresses multiple vulnerabilities found in Apache and OpenSSL.

Reboot Required: Yes

MD5 Check Sum: 187867bd991cfdd0eab0b8c0e913b0e0


Qpopper Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16409.pkg Posted:May 01, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 97,098

This update addresses a buffer overflow vulnerability found in Qpopper.
For more information, see: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0143

Reboot Required: No

MD5 Check Sum: 46730b7b3beb48f2ece82730142fd486


Wget Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16342.pkg Posted:May 01, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 346,809

This update addresses a directory traversal vulnerability in wget.
For more information see: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-1344

Reboot Required: No

MD5 Check Sum: a010a4c05392cc1486ca0f2d7dfa4125


Pine & File Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16306.pkg Posted:April 21, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 1,977,159

This update addresses vulnerabilities found in the pine mail program and the file program.

Pine was vulnerable to a remote denial of service. For more information, see http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-1320

File was vulnerable to a local buffer overflow. For more information, see http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0102

Reboot Required: No

MD5 Check Sum: 2e13e4520140d9bd3ef7e0a1e1d1f9c0


Glibc Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-15578.pkg Posted:April 17, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 24,228,174

This update addresses a security vulnerability in the glibc resolver. For more information, see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-1146

Reboot Required: Yes

MD5 Check Sum: cbcbb45e653b62c9005e7de2347c2173


Sendmail Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16429.pkg Posted:April 10, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 865,056

This patch updates the Sendmail program on your server to address a buffer overflow vulnerability. See http://www.cert.org/advisories/CA-2003-12.html for more information.

Pre-Requisites:
RaQ4-All-Security-2.0.1-16402.pkg

Reboot Required: No

MD5 Check Sum: 911dd676681b050a6c17e5733c79fb45


Kernel Update 2.0.1 C35

HTTP RaQ4-All-Kernel-2.0.1-2.2.16C35-III-1.pkg Posted:April 07, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 3,325,220

This patch will update your kernel to version 2.2.16-C35. This kernel addresses a RAID issue on the RaQ4 where synchronization of a RAID array could take a long time.

Reboot Required: Yes

MD5 Check Sum: e778ebe202cca27540d2cf28cb3ca1c8


Sendmail Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16402.pkg Posted:March 28, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 862,247

This patch updates the Sendmail program on your server to address a remote buffer overflow vulnerability. See http://www.cert.org/advisories/CA-2003-07.html for more information.

Reboot Required: No

MD5 Check Sum: 8d01bb169854393f6547d2718f8f7f56


PHP & PostgreSQL Security Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-15959.pkg Posted:March 20, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 7,025,658

This package addresses several issues with PHP and postgresql. Two PHP bugs have been fixed; the first is arbitrary command execution via the 5th parameter of mail() and the second is URL redirection using fopen(). In Postgresql, multiple buffer overruns have been recently identified and patched. In addition, Postgresql debugging is now disabled by default.

Reboot Required: Yes

MD5 Check Sum: f4798e1d90d332e23855dd5161ad5496


Root DNS server update 2.0.1

HTTP RaQ4-All-System-2.0.1-16365.pkg Posted:March 13, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 2,322

The IP address of one of the root DNS servers (J.ROOT-SERVERS.NET) has been changed. This patch updates the list of root DNS servers on your appliance.

Reboot Required: No

MD5 Check Sum: f4216e305ee5341a6e6d043667c024a1


Tar & Unzip Security update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16170.pkg Posted:March 13, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 504,087

The unzip and tar utilities contain vulnerabilities which can allow arbitrary files to be overwritten during archive extraction. See http://www.securityfocus.com/archive/1/196445 for more information.

Reboot Required: No

MD5 Check Sum: b00b98f358c6bfdd239a188938e930d9


Cgiwrap Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-16261.pkg Posted: February 14, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 41,402

This package addresses a cross-site scripting vulnerablity with cgiwrap when used with browsers that ignore input before the HTML and BODY tags.

Reboot Required: No

MD5 Check Sum: 04c0e33304a3225498ac7667ff8b4a55


Util-linux Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-15673.pkg Posted: January 08, 2003
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 857,844

The chfn binary from the util-linux package could be used to gain unauthorized access.

Reboot Required: No

MD5 Check Sum: 901504d66b3a9d5500dea101765bebce


Kernel Update 2.0.1 C33

HTTP RaQ4-All-Kernel-2.0.1-2.2.16C33III-1.pkg Posted: December 05, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 4,195,898

Kernel C33 fixes the "do_try_to_free_pages failed" VM problem under heavy load and also adds support for raw I/O.

Reboot Required: Yes

MD5 Check Sum: 0ea53b2ef29a724c16111c32b167ef17


SHP Removal 2.0.1

HTTP RaQ4-en-Security-2.0.1-SHP_REM.pkg Posted: November 21, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 1,380,859

This patch removes the SHP package. Customers who installed SHP are advised to install this patch to remove serious compatibility issues.

Reboot Required: Yes

MD5 Check Sum: ca100017bc957075ba6b142f337ef0a4


IMAP Update 2.0.2

HTTP RaQ4-All-Security-2.0.2-14936.pkg Posted: November 7, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 2,114,094

This package patches a remote buffer overflow security vulnerability in imapd.

Reboot Required: No

MD5 Check Sum: 7e28442e0a713afd91fbe5dadad920ab


IMAP Update 2.0.1 Updated by above!!!!!

HTTP RaQ4-All-Security-2.0.1-14936.pkg Posted: October 14, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 2,115,725

This patch fixes a Remote Buffer Overflow in imapd.

Reboot Required: No

MD5 Check Sum: e6e1acac14b5699068cff28ec374c332


Apache & SSL Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-2-15787.pkg Posted: September 25, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 2,829,360

This patch fixes multiple security issues with the Apache HTTP Server and OpenSSL. For more information please see:
http://online.securityfocus.com/advisories/4254
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F45509&zone_32=category%3Asecurity

Reboot Required: Yes

MD5 Check Sum: 38264ad4dfcf3f16101385a6ad139178


CGIWrap Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-14997.pkg Posted: August 27, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 40,923

This package contains an updated CGIWrap that addresses a security issue recently discovered. For more information, please see: http://online.securityfocus.com/bid/3084

Reboot Required: No

MD5 Check Sum: 579057707156df964a2e3dbf9f1f18d3


Inserted

=======================================
Software Updates For Sun Cobalt RaQ 4
Software Update Notification
08/07/02
=======================================
RaQ4-en-Security-2.0.1-SHP.pkg: Security Hardening Update
Requires Reboot: Yes
MD5 Check Sum: 4d25f4faebf22ca1f5ad10548187114b

Security Hardening patch for the Sun Cobalt RaQ 4 server appliance. Includes port scan detection and buffer overflow detection.

===================================
Sun Microsystems
Software Remove Notification
08/28/02
===================================

The version of SHP released for the Sun Cobalt RaQ 4 server appliance was found to have installation issues on some customer configurations. In addition there is a problem that could cause the /var partition of the hard disk to fill up if the system is under continuous attack. We have decided to retract the current release of SHP and release an updated version in a few days.


Update: Apache 2.0.1

HTTP RaQ4-All-System-2.0.1-15417.pkg Posted: June 28, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 2,635,768 kb

This package contains an updated Apache HTTP Server that addresses a security issue recently discovered. For more information, please see http://httpd.apache.org/info/security_bulletin_20020617.txt

MD5 Check Sum: d4055016dca256af3070c866cde2bcae

Reboot Required: Yes


Update: TCPDUMP 2.0.1

HTTP RaQ4-All-System-2.0.1-14559.pkg Posted: June 27, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 542,593 kb

This patch replaces the TCPDUMP network analysis tool with a new version. This version of TCPDUMP contains security fixes for issues that were found in prior releases of TCPDUMP for the Sun Cobalt Server Appliance.

MD5 Check Sum: ed01348f71d8ebdaac8065d444a41269

Reboot Required: No


Update: PHP Service Settings 2.0.1

HTTP RaQ4-All-System-2.0.1-14185.pkg Posted: June 18, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 2,611

This patch fixes a sync issue between what is shown in the web UI and what the actual state is on the server for the PHP service.

MD5 Check Sum: 9968454952f9e0dc773a624016df2948

Reboot Required: Yes


Update: Security Bundle 2.0.1

HTTP RaQ4-All-Security-2.0.1-13323.pkg Posted: June 18, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 20,360,962

This package upgrades the following for a varity of security concerns:

  • Bind 8.2.3-C4
  • Cyrus SASL 1.5.24-C4
  • ProFTPd 1.2.4-C2
  • urlview 0.7-5
  • Mutt 1.2.5i-C2
  • Pine 4.44-C1
  • zlib 1.1.3-25.7
  • binutils 2.11.90.0.8-12c2r4
  • CVS 1.11.1p1-6.2.C1r4
  • libstdc++ 2.95.3-1c1r4
  • GCC 2.95.3-1c1r4
  • Sed 3.02-9

MD5 Check Sum: 9968454952f9e0dc773a624016df2948

Reboot Required: No


Update: Duplicate Email Alias 2.0.1

HTTP RaQ4-All-System-2.0.1-13993.pkg Posted: May 13, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 2,796

This patch filters email alias entries preventing duplicate virtusertable entries on your server appliance.

MD5 Check Sum: 13151e1c05deb07648056b7f0f1f87c3

Reboot Required: No


Security: PHP Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-14039.pkg Posted: April 17, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 2,320,128 bytes

This patch upgrades the version of the PHP scripting engine on your server appliance. This version of PHP contains security fixes for issues that were found in prior releases of PHP for the Sun Cobalt Server Appliance.

This Update installs PHP version 4.0.6-C4. If you have upgraded PHP through a means other then packages from this website, your changes will be overwritten.

MD5 Check Sum: e640b63ed855068d7df58c17d82885a2

Reboot Required: No


Security: glibc Update 2.0.1

HTTP RaQ4-All-Security-2.0.1-13453.pkg Posted: March 13, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 24,222,502 bytes

This updates the version of glibc to fix a known vulnerability with file globbing functionality. See the following link for details: http://online.securityfocus.com/bid/3707

MD5 Check Sum: af333d0ca687404569c996f2746a4cc1

Reboot Required: Yes


Security: Kernel Update 2.0.1

HTTP RaQ4-All-Kernel-2.0.1-2.2.16C32III.pkg Posted: March 13, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 3,309,036 bytes

Updates Kernel version to C32 to fix following security alert. http://www.securityfocus.com/advisories/3607 NOTE: This package is for Sun Cobalt RaQ 4 Non-StaQware systems only. If you have Sun Cobalt StaQware running, please install kernel update at http://www.cobalt.com/support/download/staqwareraq4.html

MD5 Check Sum: 7cf79a0da0c91a0de98db51977deb430

Reboot Required: Yes


Update: DNS Update 2.0.1

HTTP RaQ4-All-System-2.0.1-12854.pkg Posted: March 13, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 3,957 bytes

This package fixes a number of issues within Sun Cobalt's DNS configuration and management interface and it's interactions with the nameserver. Moreover, after this patch, the administrator will have more options in specifying the method of RFC 2317 style reverse subnet delegation.

MD5 Check Sum: b489ef028b80ceeb30bf5db2348923f9

Reboot Required: No


OS Update 2.0

HTTP RaQ4-en-OSUpdate-2.0.pkg Posted: January 29, 2002
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 33,446,292 bytes Take note of size!!!!

This patch is an update to the Sun Cobalt RaQ 4 server appliance. It incorporates all previous patches as well as various bug fixes. See the following PDF for a complete list of bugs addressed in this update.

Prerequisites:

  • RaQ4-en-OSUpdate 1.0
  • RaQ4-All-Security-1.0.3-8762 (DOS /tmp attack)
  • RaQ4-All-System-1.0.2-9882 (DNS update)
  • RaQ4-All-Security-1.0.1-10602 (Apache Update)
  • RaQ4-All-Kernel-1.0.1-2.216C28III (Kernel Update)
More detailed information about this patch please read the following documentation:
RaQ4-en-OSUpdate-Installation.pdf

MD5 Check Sum: bd95b7cf9302cb9b7c335f99863889eb

Reboot Required: Yes


Security: Running Bind as Named Update 1.0.1

HTTP RaQ4-All-Security-1.0.1-10749.pkg Posted: November 13, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 3,305,443 bytes

This patch addresses an issue with the way named is run on Sun Cobalt Server Appliances. Currently, named is run with root permissions, this patch adds a user named 'named', and installs new initscripts to startup named with the proper arguments to run as the user named.

MD5 Check Sum: 6551930df28b21af5ba2d457ef2a2f0f

Reboot Required: Yes


Update: Kernel Update 1.0.1

HTTP RaQ4-All-Kernel-1.0.1-2.216C28III.pkg Posted: September 20, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 4,452,828 bytes

Kernel C24 and C27 would not allow the system to switch to the correct disk after a RAID failure. To correct this a new modutils has been included for the gen III Kernel so that the bandwidth module could correctly load automatically after a reboot. Also included in the update is the fix for the sysctl negative offset bug as well as the ptrace setuid bug.

MD5 Check Sum: dad1efe8427613aa4830f85068529647

Reboot Required: Yes


Security: Poprelayd 2.0-5 Update 1.0.1 This update requires reboot.

HTTP RaQ4-All-Security-1.0.1-10628.pkg Posted: September 4, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 8,256 bytes

This patch upgrades the version of poprelayd to 2.0-5. This version of poprelayd contains various security fixes for issues that were found in poprelayd v1.2.

c1d20ae882cfd49c2802c65af3c5a03a


System: Log Files Update 1.0.1

HTTP RaQ4-All-System-1.0.1-10659.pkg Posted: August 27, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 2,162 bytes

Log files are currently stored on the root partition of the server. The root partition is small, and systems storing larger than normal log files may be corrupted. This patch corrects the corruption problem by moving the growable log files to the /home partition, which has enough space to handle large files.

2048c9b82818fe373188ef6c202b9365


Security: telnetd Update 1.0.1

HTTP RaQ4-All-Security-1.0.1-10750.pkg Posted: August 22, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 69,860 bytes

This security patch addresses an issue found in the telnet daemon, where a remote attacker is able to gain access to server appliances if telnet is enabled. Information regarding this update can be found at CERT Coordination Center's website. The URL is: http://www.cert.org/advisories/CA-2001-21.html.

MD5 Check Sum: 13c7ac8315b948b85343e372203fb258


Security: Apache Update 1.0.1

HTTP RaQ4-All-Security-1.0.1-10602.pkg Posted: August 21, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 2,599,823 bytes

This patch upgrades the version of Apache to 1.3.20. This version of Apache contains various security fixes for issues that were found in prior releases of Apache for the Sun Cobalt Server Appliance.

NOTICE: This patch does not work with Chilisoft ASP 3.6. If you haveupgraded your Chilisoft ASP to 3.6, please contact Chilisoft Support for details on installing this patch with version 3.6.

MD5 Check Sum: 3b04eebff0e9f12a18415130079b0a72


Update: Mistaken Delete 1.0.1

HTTP RaQ4-All-System-1.0.1-9143.pkg Posted: August 2, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 2,463 bytes

If a user mistakenly double clicks the trashcan icon to delete a site the siteDel.cgi script will delete the entire /usr/admserv/html/.cobalt/siteManage directory. This package corrects the problem.

MD5 Check Sum: 68531bd661aa408df07a5f07ffb7597b


Security: Samba Update 1.0.1

HTTP RaQ4-All-Security-1.0.1-10260.pkg Posted: July 23, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 6,489,044 bytes

This package updates Samba to 2.0.9 in order to repair a locally exploitable security hole in previous versions. The security hole allows a user with a shell account to corrupt local devices (such as raw disks).

MD5 Check Sum: d115ef9a2209e276c00b19aaa66fc451


Security: Telnet Access 1.0.1 This update was released and pulled on June 5 - 9925 was not available then - OK to install now.

HTTP RaQ4-All-Security-1.0.1-9972.pkg Posted: July 23, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 2,354 bytes

This package fixes a security bug that gives all users of a restored (previously suspended) site telnet access.

Prerequisite: Prior to installing this update the update allowing special characters in a new username or user's full name must be installed.

RaQ4-All-System-1.0.1-9925.pkg

MD5 Check Sum: 1ecc1bf42930e47702031f37c427660c


Update: Special Characters 1.0.1 This update was posted on July 19, 2001

HTTP RaQ4-All-System-1.0.1-9925.pkg Posted: July 23, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 4,181 bytes

System problems may occur when using special characters when adding a new username or a user’s full name. This update enables the use of special characters such as “.” in a username and “’” in user’s full names

MD5 Check Sum: e369dd50a4fb951a55b9777cca8be189


Update: Reverse delegation 1.0.1

HTTP RaQ4-All-System-1.0.1-9882.pkg Posted: June 29, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 3,184 bytes

This patch fixes reverse delegations for subnets smaller than a /24. It also adds the ability to have 127.0.0.1 map to the localhost for a domain, and ensures that information relating to Secondary Name Services for networks appears in the web interface properly.

MD5 Check Sum: dea0f2693b6e79e6daf58e457c9c63aa


Security: Kernel Update 1.0.1

HTTP RaQ4-All-Kernel-1.0.1-2.216C27III.pkg Posted: June 25, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 3,357,435 bytes

This Kernel Upgrade provides a complete fix for the sysctl negative offset bug as well as the ptrace setuid bug. Information regarding this update can be found at Security Focus’ website. The URLs are:

http://www.securityfocus.com/vdb/?id=2364 - sysctl bug
http://www.securityfocus.com/vdb/?id=2044 - ptrace bug

NOTE:

  • This update should not be installed on Sun Cobalt RaQ 4r server appliances. This line was added after initial release.
  • This update is not required or intended for Sun Cobalt StaQware. It is advised that this update not be installed on Sun Cobalt StaQware.
  • The previous version of this update did not completely close the security holes mentioned above. It is strongly recommended that users install the latest Kernel version.

MD5 Check Sum: 5a2dc48fcc35b7c8284070ddb0d6542c


Security: analog Update 1.0.2

HTTP RaQ4-All-Security-1.0.2-9769.pkg Posted: May 24, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 522,712 bytes

This security update prevents a buffer overflow exploit via analog using the "alias" command. This package upgrades analog to v4.16-1(C1).

This update requires the newer version of RPM (rpm-3.0.5-9.6x) RaQ4-All-System-1.0.1-9819.pkg

For additional information please refer to http://www.analog.cx/

MD5 Check Sum: 6d3151e2ea740fe29859a341aaba4ede


Security: ntp Update 1.0.1

HTTP RaQ4-All-Security-1.0.1-10125.pkg Posted: May 23, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 385,583 bytes

The current version of ntp was found to be susceptible to buffer overflow remote root exploits. This package corrects this with updating ntp to xntp 3-5.93-14.

MD5 Check Sum: 345bf3837be7425427003724d6f4bbfe


Security: proftpd Update 1.0.1

HTTP RaQ4-All-Security-1.0.1-10108.pkg Posted: May 14, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 335,042 bytes

This patch updates proftpd in response to a CERT alert (CA-2001-07) regarding the current version of proftpd. Additional information on the patch can be located at CERT ‘s official website.: http://www.cert.org/advisories/CA-2001-07.html

MD5 Check Sum: 5327a6e1807d093b90e92f84ac3da2ed


Security: Deactivate backup.cgi Update 1.0.1

HTTP RaQ4-All-Security-1.0.1-10098.pkg Posted: May 4, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 1,869 bytes

This update prevents a copy of the backup.cgi from being created.

MD5 Check Sum: 1222e372c844a78e3205b82ee51920a5


Security: VIM Control Codes Update 1.0.1

HTTP RaQ4-All-Security-1.0.1-10014.pkg Posted: May 4, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 3,061,985 bytes

When a user opened a file in vim-enhanced or vim-X11 with the status line option enable in .vimrc, the commands would be executed as that user. This update will disable the user from embedding malicious VIM control codes into a file.

For additional information please refer to url: http://www.securityfocus.com/templates/archive.pike?list=1&mid=170642

MD5 Check Sum: 8a15d05df6ac761b4afe4adcfd16f5ff


Update: Permission to /dev/pts 1.0.1

HTTP RaQ4-All-Security-1.0.1-9847.pkg Posted: April 25, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 2,307 bytes

This update to the Sun Cobalt RaQ 4 server appliance disables global write permission to /dev/pts.

MD5 Check Sum: 4860bb192f11ca3d9168938f9867dda9


Kernel update 1.0.1

HTTP RaQ4-All-Kernel-1.0.1-2.216C24III.pkg Posted: April 25, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 3,279,008 bytes

This Kernel Upgrade provides a fix for the sysctl negative offset bug as well as the ptrace setuid bug. Information regarding this update can be found at Security Focus’ website. The urls are:
http://www.securityfocus.com/vdb/?id=2364 - sysctl bug
http://www.securityfocus.com/vdb/?id=2044 - ptrace bug

Note: This patch is not required or intended for Sun Cobalt StaQware. It is advised that this patch not be installed on Sun Cobalt StaQware.

MD5 Check Sum: cf92f40390384d555da2f331d2d6b81b


Update: RPM 1.0.1

HTTP RaQ4-All-System-1.0.1-9819.pkg Posted: April 5, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 1,569,799 bytes

This package installs a newer version of RPM (rpm-3.0.5-9.6x) and all the associated rpms
RPM: rpm-3.0.5-9.6x.i386.rpm
RPM: rpm-python-3.0.5-9.6x.i386.rpm (not on Sun Cobalt RaQ 3 server)
RPM: rpm-build-3.0.5-9.6x.i386.rpm (not on Sun Cobalt RaQ 3 server)
RPM: rpm-devel-3.0.5-9.6x.i386.rpm
RPM: popt-1.5-9.6x.i386.rpm

MD5 Check Sum: f66078327bf324ee9e81d4e18e4f7458


Security: URL Attack Exposure 1.0.1

HTTP RaQ4-All-Security-1.0.1-9844.pkg Posted: April 5, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 2,555 bytes

Security fix to remove URL attack exposure from Sun Chili!Soft ASP Samples codebrws.asp script.

This patch will remove the ability for a person to modify the URL when used in conjunction with the codebrws.asp script that ships with the Sun Chili!Soft ASP samples, to view system configuration files.

MD5 Check Sum: 2a0178cb5c03ab5aafd5fac3e3d92aa7


Security: Backup Update 1.0.1

HTTP RaQ4-All-Security-1.0.1-9878.pkg Posted: March 23, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 2,265 bytes

This patch addresses an issue found in backup that allows local users to run arbitrary commands with elevated user privileges.

MD5 Check Sums: 0d786e16a55484dffa26137941392559


Recovery Update 1.0.2

HTTP RaQ4-en-System-1.0.2-9198.pkg Posted: March 9, 2001
FTP Point your FTP client to ftp://ftp.cobalt.com Size: 13,439,716 bytes