HP Tru64 UNIX and TruCluster Server Version 5.1.B-4 Patch Summary and Release Notes (13156)
• Corrects a potential security vulnerability where, under certain circumstances, system
integrity may be compromised. This may be in the form of improper file access.
• Corrects a problem in which when DHCP is selected for a network interface card, netconfig
places invalid data in the /etc/hosts file.
• Changes the use of the configuration file /etc/svc.conf to /etc/nsswitch.conf to allow netgroup
data to be provided from LDAP, rather than only from NIS.
• Fixes a problem in the SysMan nfs_export application in which adding a host to the rw-access
list does not take effect.
• Fixes a problem in the SysMan nfs_export application in which an inappropriate message
is displayed when a nonroot user runs it.
• Corrects a problem in which the network wizard exits when running as nonroot.
• Corrects a potential security vulnerability in IPsec/IKE (Internet Key Exchange) with
Certificates. This potential vulnerability is remotely exploitable, resulting in unauthorized
privileged access.
SSRT3674 - IPsec/IKE (Severity - High)
• Fixes a problem in which SysMan route does not handle the destination name input correctly
Patch 27062.00
OSFNFS540
• Fixes multiple defects in AutoFS user space and kernel code.
• Enables mountd to correctly handle entries with multiple lines of input in an exports file.
• Makes start-up scripts in /sbin/init.d world readable.
• Fixes an issue with the rpc.lockd daemon's message passing-style RPCs, where replies are
sent to the IP address of the lock's caller_name field instead of to the call message's source.
• Modifies the mountd daemon to correct a core dump problem.
• Restore exports file (-root=hostlist) behavior.
• Changes the use of the configuration file /etc/svc.conf to /etc/nsswitch.conf to allow netgroup
data to be provided from LDAP, rather than only from NIS.
• Enables AutoFS to handle loopback mounts correctly, specifically regarding failed attempts
to use AutoFS to access a loopback mount via a cluster alias.
• Fixes the behavior of the rpc.rquotad daemon in a cluster.
• Addresses a mountd problem in which spurious signals can cause mountd to dump core
and a second problem that causes .INCLUDE parsing to function incorrectly.
• Enables AutoFS mount-on paths to have the correct maximum length when AutoFs files are
mapped directly.
• Fixes an rpc.lockd problem involving lock contention, in which lock requests accumulate
on a linked list that is searched with each kernel lock manager poll and result in excessive
CPU consumption
• Fixes an issue in which an error was being reported with an empty direct map.
• Fixes a problem where rpc.statd does not correctly create the sm and sm.bak directories on
startup, causing rpc.statd to exit.
3.4 Summary of Base Operating System Patches 133