Document ID: 271040
http://support.veritas.com/docs/271040
E-Mail Colleague IconE-Mail this document to a colleague

A security flaw which allows for potential unauthorized root access in VERITAS Cluster Server (tm) for all UNIX platforms has been discovered

Details:
The potential for a serious system security breach has been found to exist in VERITAS Cluster Server for Solaris, HP-UX, AIX, and Linux. This issue does not exist on any version of VERITAS Cluster Server for Windows. The potential problem has been addressed for Solaris, HP-UX, AIX, and Linux versions of Cluster Server in the patches listed below.  If you have VERITAS Cluster Server 4.0 on Solaris and have already applied MP1, then this issue is already resolved in your environment. It is highly recommended that all installations of Cluster Server be updated to include the fix for this potential security issue because root access can be achieved by unauthorized users.

To obtain the patch needed for your installation of Cluster Server, follow these steps:

1. Find the appropriate UNIX platform and version in the list below
2. Verify that you have the appropriate version of Cluster Server installed on which to apply the patch (check the table below)
3. Open and read the listed TechFile for your platform (the TechFile numbers in the list below are links to the document)
4. Download the patch directly from that TechFile

Note: If using VERITAS CommandCentral (tm) Availability, you must apply the Command Central Availability patch from TechFile  http://support.veritas.com/docs/270142 for Command Central Availability to work with Cluster Server after having applied any of the patches below.

 
PlatformCD release versionVCS versionTechFileChecking the VCS version
Solaris3.5 MP33.5p3270071pkginfo VRTSvcs
Solaris4.04.0269487pkginfo VRTSvcs
HP-UX3.5 Update 23.5p1270074swlist VRTSvcs
AIX3.5 MP13.5p1270090lslpp -L VRTSvcs.rte
RedHat Advanced Server 2.1 i6862.2 MP22.2p2270095rpm -qa VRTSvcs
RedHat Enterprise Linux 3.0 i6862.2 MP22.2p2270096rpm -qa VRTSvcs
RedHat Enterprise Linux 3.0 update 2 IA642.2 MP22.2p2270097rpm -qa VRTSvcs
SuSE SLES 8 SP32.2 MP22.2p2270092rpm -qa VRTSvcs
ESX2.2 MP22.2p2271277rpm -qa VRTSvcs


Note: Because this is a security issue, VERITAS will not publicly disclose details of this issue. If you require assistance in applying the patch or insuring that your system is upgraded to the necessary levels, or assistance in determining which systems are potentially vulnerable to this issue, please contact VERITAS Technical Support.



Supplemental Material:

System: Ref.#Description
iTools: 147547 Potential security flaw found


Products Applied:
 Cluster Server for UNIX 1.0.1 (Solaris), 1.0.2 (Solaris), 1.1 (Solaris), 1.1.1 (Solaris), 1.1.2 (Solaris), 1.3.0 (Solaris), 1.3.0 (Solaris) PRE-GA, 1.3.0P1, 1.3.0P2, 1.3.0P3, 1.3.0P4, 1.3.1 (HPUX), 1.3.1P3, 2.0 (AIX), 2.0 (Linux), 2.0 (Solaris), 2.0 (Solaris) BETA, 2.0 (Solaris) GA, 2.0P1, 2.0P2, 2.0P3, 2.0P4, 2.1, 2.1 (Linux), 2.1 P1 (Linux), 2.2, 2.2 (Linux), 2.2 MP1, 2.2 MP1P1 (Linux), 2.2 MP2, 3.5 (AIX), 3.5 (HPUX), 3.5 (Solaris), 3.5 (Solaris) BETA, 3.5 MP1, 3.5 MP1 (Solaris), 3.5 MP1J, 3.5 MP2, 3.5 MP2 (Solaris), 3.5 MP3 (Solaris), 3.5 P1, 3.5 Update 1 (HPUX), 3.5 Update 2 (HPUX), 3.5.1 (AIX), 4.0 (AIX), 4.0 (AIX) Beta, 4.0 (Linux), 4.0 (Linux) BETA, 4.0 (Solaris), 4.0 (Solaris) BETA, 4.0 MP1 (Solaris) (Fixed)
 CommandCentral Availability 4.0, 4.0 BETA

Last Updated: October 14 2004 06:01 PM GMT
Expires on: 02-22-2005
Subscribe Via E-Mail IconSubscribe to this document

Subjects:
 AIX
   Application: Informational
Cluster Server for UNIX
   Application: Alert, Informational, Patches
   Publishing Status: Techalert
CommandCentral Availability
   Application: Patches
   Publishing Status: Techalert
HP-UX
   Application: Informational, Patches
Linux
   Applications: Information, Patches
Solaris
   Application: Informational, Patches

Languages:
 English (US)

Operating Systems:
AIX

4.3.3, 4.3.4, 5.1, 5.2

HP-UX

11.0, 11.11

Solaris

2.6, 7.0, 8.0, 9.0

Linux

RedHat Advanced Server 2.1, RedHat Enterprise Linux 3.0 (AS, ES, WS), RedHat Enterprise Linux 3.0 U2 (AS, ES, WS), SLES 8 SP2/SP2a

VMWare ESX

2.1


Was this article helpful to you?
Yes   No

If any information was unclear, or the information you were seeking was not provided, please let us know. Your feedback will help us improve this service.

NOTE: Comments entered here will NOT receive a personal e-mail response. If you need a VERITAS Technical Support representative to respond to your issue, please click here to send us an e-mail.