Monday, July 19, 2010

SUN ALERT WEEKLY SUMMARY REPORT

Description


For weeks:
04-Jul-2010 to 10-Jul-2010
27-Jun-2010 to 03-Jul-2010
20-Jun-2010 to 26-Jun-2010
13-Jun-2010 to 19-Jun-2010
06-Jun-2010 to 12-Jun-2010
30-May-2010 to 05-Jun-2010
23-May-2010 to 29-May-2010
16-May-2010 to 22-May-2010
09-May-2010 to 15-May-2010
02-May-2010 to 08-May-2010
25-Apr-2010 to 01-May-2010
18-Apr-2010 to 24-Apr-2010
11-Apr-2010 to 17-Apr-2010
04-Apr-2010 to 10-Apr-2010
28-Mar-2010 to 03-Apr-2010
21-Mar-2010 to 27-Mar-2010
14-Mar-2010 to 20-Mar-2010

Newly released and updated Sun Alerts on SunSolve are now available under the SURE collection by using "Advanced Search > Sun Alerts (SURE)".

For additional Security information, please visit:

******************************************************************************************
04-Jul-2010 to 10-Jul-2010

Updated:

Alert ID 1143914.1 - Installation of Microsoft Security Update KB980232 on Windows Systems That Access ST5210/5220/5310/5320 NAS Systems May Cause Loss of File Access/File Descriptors

===============================================================

27-Jun-2010 to 03-Jul-2010

Updated:

Alert ID: 1021811.1 - Solaris Daylight Saving Time (DST) Update (Jan through Jun 2010)

Alert ID: 1021781.1 - A Security Vulnerability in the ntp Daemon (xntpd(1M)) May Lead to a Denial of the Solaris Network Time Protocol (NTP) Service

===============================================================

20-Jun-2010 to 26-Jun-2010

Newly Released:

Alert ID: 1134162.1 - Abrupt System Reboot may Lead to ZFS Filesystem Data Integrity Issues

Updated:

Alert ID: 1021653.1 - Security Vulnerability in the Transport Layer Security (TLS) and Secure Sockets Layer 3.0 (SSLv3) Protocols Involving Handshake Renegotiation Affects OpenSSL

===============================================================

13-Jun-2010 to 19-Jun-2010

Newly Released:

Alert ID: 1124204.1 - Solaris 10 patches 141444-09/141445-09 May Cause EFI Labeled LUNs to Become Inaccessible Due to Incorrect Device Nodes Being Presented

Alert ID: 1128433.1 - Solaris 10 NFS Patches and Certain OpenSolaris Builds May Cause an NFSv4 Client to Panic

Alert ID: 1128605.1 - Firmware for RAID Controllers Causes Unscheduled Simultaneous Reboot of Controllers After 828.5 Days of Continuous Operation

Updated:

Alert ID: 1109368.1 - Solaris 10 Using Soft Rings May Panic in ip_squeue_set_unbind and Applications May Hang with Patch 142900-03/142901-03 Installed

===============================================================

06-Jun-2010 to 12-Jun-2010

Newly released:

Alert ID: 1116894.1 - ZFS Pool Upgrade may Cause a System Panic and Potentially Lead to Data Integrity Issues

Updated:

Alert ID: 1021797.1 - A Security Vulnerability Relating to Certificate Handling in sendmail(1M) Versions Prior to 8.14.4 May Allow Server Identification Forgery

Alert ID: 1021798.1 - Multiple Security Vulnerabilities in BIND DNSSEC Software Shipped With Solaris May Cause Bogus NXDOMAIN Responses

Alert ID: 1021684.1 - Solaris autopush(1M) Changes (with patches 141444-09/141511-04) May Cause Sun Cluster 3.1 and 3.2 Nodes to Hang During Boot

===============================================================

30-May-2010 to 05-Jun-2010

Alert ID: 1116047.1 - Solaris Systems With SVM Configured With Root Mirrored may Hang on Reboot After the Addition of a New Device

===============================================================

23-May-2010 to 29-May-2010

Alert ID: 1019880.1 - Solaris 10 With Patches 137137-09 (SPARC) or 137138-09 (x86) May Fail to Boot if ZFS Boot is Enabled

Alert ID: 1109368.1 - Solaris 10 Using Soft Rings May Panic in ip_squeue_set_unbind and Applications May Hang with Patch 142900-03/142901-03 Installed

===============================================================

09-May-2010 to 15-May-2010

No updated or newly released Sun Alerts during this time period.

===============================================================

09-May-2010 to 15-May-2010

No updated or newly released Sun Alerts during this time period.

===============================================================

02-May-2010 to 08-May-2010

Alert ID: 280030
HIPER - Oracle StorageTek HSC Abnormally Terminates with ABEND U1096 RC=1729070D

Alert ID: 279830
Installation of Microsoft Security Update KB980232 on Windows Systems That Access
ST5210/5220/5310/5320 NAS Systems May Cause Loss of File Access/File Descriptors

================================================================

25-Apr-2010 to 01-May-2010

Alert ID: 276190
Solaris Daylight Saving Time (DST) Update (Jan through Apr 2010)

Alert ID: 275890
Multiple Security Vulnerabilities in BIND DNSSEC Software Shipped With Solaris
May Cause Bogus NXDOMAIN Responses

Alert ID: 273169
Security Vulnerability in BIND DNS Software Shipped With Solaris May Allow DNS Cache Poisoning


Alert ID: 279850
HIPER-Oracle StorageTek Virtual Tape Control System (VTCS) Data Loss may Occur
Following Execution of the LOGUTIL/GENAUDIT Command Processing


===============================================

18-Apr-2010 to 24-Apr-2010

Alert ID: 269808
Improper AC Input Power Supply Redundancy Testing on Sun SPARC Enterprise
M4000/M5000 Servers May Result in Domain Outages, or Cause Components to
be Falsely Marked as Faulty


=================================================================

11-Apr-2010 to 17-Apr-2010

Alert ID: 274590
This Alert Covers CVE-2010-0888 for the Device Services Component of the
Sun Ray Server Software Product


---------------------------------------------------------------
Alert ID: 275910
This Alert Covers CVE-2010-0453 for the /dev/ucode Component of the Solaris
and OpenSolaris Products.


---------------------------------------------------------------
Alert ID: 276130
This Alert covers CVE-2010-0883 and CVE-2010-0884 for the Data
Service for Oracle E-Business Suite component of the Sun Cluster product.


---------------------------------------------------------------
Alert ID: 276090
This Alert Covers CVE-2010-0893 for the Mail Component of the Sun Convergence Product


---------------------------------------------------------------
Alert ID: 248666
This Alert Covers CVE-2010-0891 for the Sun Management Center Product


---------------------------------------------------------------
Alert ID:
This Alert covers CVE-2010-0882 for the Trusted Extensions component
of the Solaris and OpenSolaris products.


---------------------------------------------------------------
Alert ID: 267568
This Alert Covers CVE-2010-0894 for the Sun Java System Access Manager Product


---------------------------------------------------------------
Alert ID: 276411
This Alert covers CVE-2010-0896 for the mail component of the Sun Convergence product.


---------------------------------------------------------------
Alert ID: 273910
This Alert covers CVE-2009-2404 and CVE-2009-0688 for the Directory
Server component of the Sun ONE Directory Server and Sun Java System
Directory Server products.


---------------------------------------------------------------
Alert ID: 242386
This Alert covers CVE-2010-0890 for the kernel component of the Solaris
and OpenSolaris products.

---------------------------------------------------------------
Alert ID: 276533
This Alert covers CVE-2010-0895 for the IP Filter component of the OpenSolaris product.


---------------------------------------------------------------
Alert ID: 273850
This Alert covers CVE-2010-0889 for the kernel component of the Solaris
and OpenSolaris products.


---------------------------------------------------------------
Alert ID: 276210
This Alert covers CVE-2010-0897 for the Sun Java System Directory Server product.


---------------------------------------------------------------
Alert ID: 276630
This Alert covers the Address Book component of the Sun Java System
Communications Express product.


---------------------------------------------------------------
Alert ID: 279590
Oracle Security Alert for CVE-2010-0886 was released on April 15th, 2010.


=================================================================

04-Apr-2010 to 10-Apr-2010:

Alert ID: 276190
Title: Solaris Daylight Saving Time (DST) Update (Jan through Apr 2010)
Product: Solaris 8, Solaris 9 Operating System, Solaris 10 Operating System
Category: Availability
Release Phase: Resolved
Workaround Date: 01-Feb-2010
Updated Date: 05-Mar-2010


---------------------------------------------------------------

Alert ID: 279170
Title: Using Common Array Manager (CAM) 6.6.0.11 to Create a New Initiator
may Result in the Incorrect Host Type Being Used
Product: Sun StorageTek Common Array Manager Software 6.6
Category: Availability
Release Phase: Workaround
Date of Workaround: 05-Apr-2010


---------------------------------------------------------------

Alert ID: 279210
Title: ServiceTek Plus (STP) "Phone-Home" Capability Will Cease to Operate
for Legacy StorageTek Products in October 2010
Product: STP (BIDW)
Category: Availability
Release Phase: Resolved
Date of Resolved: 07-Apr-2010


===============================================================

28-Mar-2010 to 03-Apr-2010:

Alert ID: 273169
Title: Security Vulnerability in BIND DNS Software Shipped With Solaris May Allow
DNS Cache Poisoning
Product: Solaris 9 Operating System, Solaris 10 Operating System, OpenSolaris
Category: Security
Release Phase: Workaround
Workaround Date: 24-Nov-2009
Updated Date: 31-Mar-2010


================================================================

21-Mar-2010 to 27-Mar-2010:

Alert ID: 273551
Title: Two Security Vulnerabilities in GNU tar (see gtar(1)) May Lead to Files Being
Overwritten, Execution of Arbitrary Code, or a Denial of Service (DoS)
Product: Solaris 10 Operating System, OpenSolaris
Category: Security
Release Phase: Resolved
Resolved Date: 23-Mar-2010

To view this Alert document please go to the following URL:

=================================================================
14-Mar-2010 to 20-Mar-2010:

Alert ID: 275530
Title: Integer Overflow Security Vulnerability in AES and RC4
Decryption in the Solaris Kerberos Crypto Library May
Lead to Execution of Arbitrary Code or a Denial of
Service (DoS)
Product: Solaris 10 Operating System, OpenSolaris
Category: Security
Release Phase: Resolved
Resolved Date: 18-Mar-2010

To view this Alert document please go to the following URL:

-----------------------------------------------------------------

Alert ID: 242426
Title: The "zpool create" Command May Dump Core When Used on
Systems Running Sun Cluster 3.2
Product: Solaris Cluster 3.2
Category: Availability
Release Phase: Resolved
Resolved Date: 01-Dec-2008
Last Updated: 17-Mar-2010

To view this Alert document please go to the following URL:

-----------------------------------------------------------------

Alert ID: 275590
Title: A Security Vulnerability in the ntp Daemon (xntpd(1M))
May Lead to a Denial of the Solaris Network Time
Protocol(NTP) Service
Product: Solaris 8 Operating System, Solaris 9 Operating System,
Solaris 10 Operating System, OpenSolaris
Category: Security
Release Phase: Workaround
Workaround Date: 13-Jan-2010
Last Updated: 18-Mar-2010

To view this Alert document please go to the following URL:

=================================================================

Comments and questions can be sent to:
sunalert-newsletter@sun.com

To subscribe to this document, go to:


In the right column under Page Tools, select "Subscribe To This Article".
To unsubscribe, select "View/Edit Subscriptions".

No comments:

Post a Comment