Sun Alert Notifications from Sun Weekly Report dated Nov 11, 2006

Original Release Date: February 6, 2007
Last Revised: September 17, 2008
Number: ASA-2007-006
Risk Level: Low
Advisory Version: 2.0
Advisory Status: Final

1. Overview:

New Sun Alert Notifications from Sun Microsystems have been issued and are described below. Issues which have been resolved by Sun Microsystems have been indicated as such. Notifications without a resolution may have restrictions to additional information on the sunsolve.sun.com website.

102452
Logical Drives May be Lost if "auto-global-spare" is Enabled
Product: Sun StorEdge 3310 SCSI Array, Sun StorEdge 3510 FC Array, Sun StorEdge 3320 SCSI Array, Sun StorEdge 3511 SATA Array
Category: Data Loss
Date Released: 09-Nov-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102452-1
102690
Certain Solaris 9 and 10 "mpt" Driver Patches may Cause a System Panic on Reboot or Fail to Recognize Drives
Product: Solaris 9 Operating System, Solaris 10 Operating System
Category: Availability
Date Released: 09-Nov-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102690-1
102711
Security Vulnerabilities in OpenSSL May Lead to a Denial of Service (DoS) to Applications or Execution of Arbitrary Code With Elevated Privileges
Product: Solaris 9 Operating System, Solaris 10 Operating System
Category: Security
Date Released: 09-Nov-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102711-1
102712
Possible Data Integrity Issues on Solaris 10 Systems Using the e1000g Driver for the Intel Gigabit Network Interface Card (NIC)
Product: Solaris 10 Operating System
Category: Data Loss
Date Released: 10-Nov-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102712-1

Avaya System Products using a Sun Microsystems Operating System:
Avaya system products include an Operating System with the product when it is delivered. The Avaya Call Management System (CMS) and the Avaya Interactive Response (IR) are both shipped with an operating system from Sun Microsystems. Actions to be taken on those products are described below.

Recommended Actions:
Follow the recommended actions for the notifications described below. This advisory will be updated as additional information becomes available.

Sun Advisory: Affected S/W Version Risk Comments or Recommended Actions
102452 CMS - All

IR - All
None

None
CMS does not use StorEdge devices.

IR does not use StorEdge devices.
102690 CMS - All

IR - All
None

None
CMS is not affected as the problematic patches are not installed by default.

IR does not use the affected SCSI Host Adapters by default.
102711 CMS - All

IR - 2.0 on Solaris 10
None

Low
CMS does not use Solaris 10. While the summary from Sun says Solaris 9 is affected, the body of the advisory only mentions Solaris 10.

For IR 2.0 on Solaris 10 install Solaris 10 Patch Cluster for Avaya IR 2.0 Service Pack 3.
102712 CMS - All

IR - 2.0 on Solaris 10, 3.0
None

Low
CMS does not use Solaris 10.

Sun Fire 280R systems are affected.
For IR 2.0 on Solaris 10 install Solaris 10 Patch Cluster for Avaya IR 2.0 Service Pack 3
For IR 3.0 install Solaris 10 Patch Cluster for Avaya IR 3.0 Service Pack 2

2. Additional Information:

Additional information may also be available via the Avaya support website and through your Avaya account representative. Please contact your Avaya product support representative, or dial 1-800-242-2121, with any questions.

3. Disclaimer:

ALL INFORMATION IS BELIEVED TO BE CORRECT AT THE TIME OF PUBLICATION AND IS PROVIDED "AS IS". AVAYA INC., ON BEHALF ITSELF AND ITS SUBSIDIARIES AND AFFILIATES (HEREINAFTER COLLECTIVELY REFERRED TO AS "AVAYA"), DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE AND FURTHERMORE, AVAYA MAKES NO REPRESENTATIONS OR WARRANTIES THAT THE STEPS RECOMMENDED WILL ELIMINATE SECURITY OR VIRUS THREATS TO CUSTOMERS' SYSTEMS. IN NO EVENT SHALL AVAYA BE LIABLE FOR ANY DAMAGES WHATSOEVER ARISING OUT OF OR IN CONNECTION WITH THE INFORMATION OR RECOMMENDED ACTIONS PROVIDED HEREIN, INCLUDING DIRECT, INDIRECT, CONSEQUENTIAL DAMAGES, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF AVAYA HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

THE INFORMATION PROVIDED HERE DOES NOT AFFECT THE SUPPORT AGREEMENTS IN PLACE FOR AVAYA PRODUCTS. SUPPORT FOR AVAYA PRODUCTS CONTINUES TO BE EXECUTED AS PER EXISTING AGREEMENTS WITH AVAYA.

4. Revision History:

V 1.0 - February 6, 2007 - Initial Statement issued.
V 2.0 - September 17, 2008 - Changed ASA status to final, IR recommended actions for Sun advisories 102711 and 102712, and IR affected versions for Sun advisory 102712.

Send information regarding any discovered security problems with Avaya products to either the contact noted in the product's documentation or securityalerts@avaya.com.

© 2007 Avaya Inc. All Rights Reserved. All trademarks identified by the ® or ™ are registered trademarks or trademarks, respectively, of Avaya Inc. All other trademarks are the property of their respective owners.