-----BEGIN PGP SIGNED MESSAGE-----
===============================================================================
Security Advisory CERT-NL
===============================================================================
Author/Source : Teun Nijssen Index : S-97-20
Distribution : World Page : 1
Classification: External Version: 1
Subject : Digital UNIX Division of Privilege (DoP) Date : 17-Mar-97
===============================================================================
By courtesy of Digital Equipment Corporation and CERT Coordination Center
we received the following information.
In CERT Coordination Center Vendor-Initiated Bulletin VB-97.01.dec
Digital reports a vulnerability in Division of Privilege (DoP),
"/usr/sbin/dop" for DIGITAL UNIX V4.0, V4.0A and V4.0B
This vulnerability allows an unauthorized user to gain unauthorized
privileges.
This advisory provides information about a patch available at
ftp://ftp.service.digital.com/public/ the sub directory Digital_UNIX,
key identifier SSRT0435U
CERT-NL recommends to apply the patch as soon as possible.
All CERT Coordination Center advisories and bulletins are mirrored
by CERT-NL. The specific URL for this case is:
ftp://ftp.surfnet.nl/surfnet/net-security/
cert-cc-mirror/cert_bulletins/VB-97.01.dec
More information about the CERT-NL mirror and notifier services is
contained in News items N-95-01 (notifier) and N-95-02 (CERT mirror),
both present on
==============================================================================
CERT-NL is the Computer Emergency Response Team for SURFnet customers.
SURFnet is the Dutch network for educational, research and related institutes.
CERT-NL is a member of the Forum of Incident Response and Security Teams
(FIRST).
All CERT-NL material is available under:
In case of computer or network security problems please contact your
local CERT/security-team or CERT-NL (if your institute is NOT a SURFnet
customer please address the appropriate (local) CERT/security-team).
CERT-NL is one/two hour(s) ahead of UTC (GMT) in winter/summer,
i.e. UTC+0100 in winter and UTC+0200 in summer (DST).
Email: cert-nl@surfnet.nl
Phone: +31 302 305 305
Fax: +31 302 305 329
Snailmail: SURFnet bv
Attn. CERT-NL
P.O. Box 19035
NL - 3501 DA UTRECHT
The Netherlands
A 7 * 24 hours phone number is available to SURFnet SSC's and FIRST
members on request.
==============================================================================
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: cp850
iQCVAgUBMy1Uc0U5nQkWIq1FAQEvSwP9F1YyBp2p4J1/wReM8Wcis81+VQHoWqHr
S08QRNEcaGlJVi0BovWFdVrPYXdFaxdZwXxBM3772OMGHUcPpZLYnnFZESj8mW2c
5yr4pVxPYbVu/aWAw3EYN2cTYSCmeiS8v30ndpeF5ysDWq5dxAIxKw0a1N87rplR
xhurCesTesU=
=9XLc
-----END PGP SIGNATURE-----