What is Security Supplement p535239a, the sco_pmd security fix for UnixWare 7.1.4? KEYWORDS: unixware 7.1.4 714 security supplement p535239a fz535239 SCOSA-2011.1 sco_pmd dos denial service vulnerability RELEASE: SCO Unixware Release 7.1.4 PROBLEM: What is Security Supplement p535239a, the sco_pmd security fix for UnixWare 7.1.4? SOLUTION: The supplement fixes a potential DOS vulnerability of sco_pmd. What follows is the Security Advisory for this fix: ______________________________________________________________________________ SCO Security Advisory Subject: sco_pmd security fix for UnixWare 7.1.4 Advisory number: SCOSA-2011.1 Issue date: 20th July 2011 Cross reference: fz535239 ______________________________________________________________________________ 1. Problem Description Security Supplement p535239a, the sco_pmd security fix for UnixWare 7.1.4, addresses a potential denial of service vulnerability of sco_pmd. 2. Vulnerable Supported Versions System Package ---------------------------------------------------------------------- UnixWare 7.1.4 uw714mp4 3. Solution The proper solution is to install the relevant package below. 4. UnixWare 7.1.4 This patch should only be installed on UnixWare 7.1.4 systems with Maintenance Pack 4 installed. 4.1 Location of Fixed Binaries ftp://ftp.sco.com/pub/unixware7/714/security/p535239a_uw7/ 4.2 Verification # sum -r p535239a.image 51634 178 p535239a.image MD5 (p535239a.image) = b7828b6a62f20f9739c1a4ea7d5667cd md5 is available for download from ftp://ftp.sco.com/pub/security/tools 4.3 Installation Instructions 1. Download the p535239a.image file to the /tmp directory on your machine. 2. As root, add the package to your system using these commands: $ su - Password: # pkgadd -d /tmp/p535239a.image Alternatively, this package may be installed in quiet mode, that is, without displaying the release notes and asking for confirmation. To do this, use these commands: $ su - Password: # pkgadd -qd /tmp/p535239a.image all 3. Reboot the system after installing this package. 4.4 Removal Instructions 1. As root, remove the package using these commands: $ su - Password: # pkgrm p535239 2. Reboot the system after removing this package. 5. References SCO security resources: http://www.sco.com/support/download.html SCO security advisories via email http://www.sco.com/support/forums/security.html This security fix closes SCO incidents fz535239. 6. Disclaimers SCO is not responsible for the misuse of any of the information we provide on this website and/or through our security advisories. Our advisories are a service to our customers intended to promote secure installation and use of SCO products. 7. Acknowledgments N/A