Re: [Stronghold-support-world] SH 4.0 vulnerabilities

Min Min Tsan <[email protected]> Mon, 7 Oct 2002 13:39:30 +0100
Newsgroups gmane.linux.redhat.stronghold
Message-ID <[email protected]>
Hello,

The latest released version of Stronghold 4.0 has all the old, known 
vulnerabilities fixed and is available via the automatic update 
services. For instance, to update a Stronghold 4.0 installation for Red 
Hat Linux Advanced Server using the Red Hat Network, please run:

  # up2date

To update a Stronghold 4.0 installation on other Unix platforms, please 
run:

  $ bin/agent

from <ServerRoot> (the main directory where you installed Stronghold).  
This will ensure you have the latest security and bug fixes for your 
Stronghold installation. We'll be sending you detailed instructions 
directly in an email following this.

We are sorry that it is not available in the CD provided in media kit 
because the media is produced in bulk. Our media production cycle 
has a fixed schedule so it takes time to have the new version in the CD.

We would like to apologise for any inconveniences caused and please feel 
free to contact us if you require further information.

Thank you for using Stronghold.

Kind regards,
Min Min
--
Red Hat Stronghold Support                    tel: +44 1483 300 169 
http://www.redhat.com/support/resources/      fax: +44 1483 734 929
http://www.redhat.com/software/apache/stronghold/                  

On Fri, Oct 04, 2002 at 02:52:57PM -0700, Raynard A. Jong wrote:
> I was forced to upgrade from SH 2.4.2 to SH 4.0 because fixes for the 
> Linux slapper vulnerability were not available from RedHat for the 
> older version of Stronghold.
> 
> So after spending my $1000 to get the latest version, what do I get? 
> The CD I receive has version  Stronghold 4.0 that has the Apache HTTP 
> server chunked encoding heap buffer overflow as well as the Openssl 
> SSL2 master key buffer overflow.
> 
> What  a disappointment.  It doesn't say much for RedHat.  When you 
> purchase a product, you should at expect that all the old, known 
> vulnerabilities should be removed.