Patch-ID# 104477-04 Keywords: security in.ftpd ftp Synopsis: SunOS 4.1.4: ftp and in.ftpd fixes Date: Aug/26/98 Solaris Release: 1.1.2 SunOS Release: 4.1.4 Unbundled Product: Unbundled Release: Relevant Architectures: sparc NOTE: sun4(all) BugId's fixed with this patch: 1246408 1198215 4011498 4080226 Changes incorporated in this version: 4080226 Patches accumulated and obsoleted by this patch: Patches which conflict with this patch: Patches required with this patch: Obsoleted by: Files included with this patch: ftp in.ftpd Problem Description: 4080226 Security issue: security hole in mget (on ftp client) 1246408 ftp can gain root access from port 20 to other systems 1198215 ftp can silently lose data when writing to nfs 4011498 ftp fails with multiple access requests to the server Patch Installation Instructions: 1. su root 2. cd 3. mv /usr/etc/in.ftpd /usr/etc/in.ftpd.FCS mv /usr/ucb/ftp /usr/ucb/ftp.FCS 4. cp in.ftpd /usr/etc/in.ftpd chown root.staff /usr/etc/in.ftpd cp ftp /usr/ucb/ftp chown root.staff /usr/ucb/ftp