SUNWlldap vulnerability

"Brent J. Nordquist" <[email protected]>
Newsgroups gmane.comp.security.sun
Message-ID <[email protected]>
The listing at http://securityfocus.com/bid/7064 says that Solaris x86's
LDAP code is vulnerable when resolving host names that are too long.  I
think I'm inferring from the README for patch 108993-13 (Solaris 8 SPARC)
that Solaris SPARC is vulnerable too.

The problem is that 108993-13 requires a minimum pthreads patch level,
which requires a minimum kernel patch level, and both of those require a 
reboot.  This one will be a pain to deploy.

I haven't seen any discussion on this issue (Bugtraq etc.) so I'm trying
to figure out how serious the vulnerability is.  What have other people
decided about installing 108993-13?  Has anyone determined which code that
links with LDAP libraries might be vulnerable, and how (local or remote, 
root, etc.)?

-- 
Brent J. Nordquist <[email protected]> N0BJN
Other contact information: http://kepler.acns.bethel.edu/~bjn/contact.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.