Sun Alert Notifications from Sun Weekly Report dated Jan 14, 2006

Original Release Date: February 23, 2006
Last Revised: March 6, 2006
Number: ASA-2006-056
Risk Level: Low
Advisory Version: 2.0
Advisory Status: Final

1. Overview:

New Sun Alert Notifications from Sun Microsystems have been issued and are described below. Issues which have been resolved by Sun Microsystems have been indicated as such. Notifications without a resolution may have restrictions to additional information on the sunsolve.sun.com website.

101933 (RESOLVED)
Security Vulnerabilities in uucp(1C) and uustat(1C)
Date Released: 09-Jan-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101933-1
102033 (RESOLVED)
Vulnerabilities in lpsched(1M) May Allow an Unprivileged User to Remove System Files or Disable the LP Service
Date Released: 13-Jan-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102033-1
102066 (RESOLVED)
Security Vulnerability May Allow An Unprivileged Local User to Gain Root Access or Panic the OS
Date Released: 11-Jan-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102066-1
102087 (RESOLVED)
Solaris 10 x86 Platform GRUB Bootloader Architecture and Kernel Patch 118844-27
Date Released: 11-Jan-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102087-1
102098
Insufficient Information for Recovery From Double Drive Failure for Sun StorEdge 33x0/35xx Arrays Date
Date Released: 12-Jan-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102098-1
102106 (RESOLVED)
Booting From a Sun StorEdge 6920 Release 3.0 (Running Baseline 3.0.0.25) May Fail With "Fast Data Access MMU Miss" Errors
Date Released: 11-Jan-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102106-1
102108 (RESOLVED)
Security Vulnerability Using find(1) to Search "/proc" May Cause a Denial of Service (DoS) Condition
Date Released: 11-Jan-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102108-1
102124
Solaris 10 x86 Platform Patches 118345-05 or Later and 118565-03 or Later May Cause a System Hang
Date Released: 09-Jan-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102124-1
102126
Recovery Behavior From Fatal Drive Failure May Lead to Data Integrity Issues
Date Released: 12-Jan-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102126-1
102127
Performance Degradation Reported in Controller Firmware Releases 4.1x on Sun StorEdge 3310/351x Arrays for All RAID Types and Certain Patterns of I/O
Date Released: 12-Jan-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102127-1
102128
Data Inconsistencies May Occur When Persistent SCSI Parity Errors are Generated Between the Host and the SE33x0 Array
Date Released: 12-Jan-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102128-1
102129
Disks May be Marked as Bad Without Explanation After "Drive Failure," "Media Scan Failed" or "Clone Failed" Events
Date Released: 12-Jan-2006
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102129-1

Avaya System Products using Sun Microsystems:
Avaya system products include an Operating System with the product when it is delivered. The Avaya Call Management System (CMS) and the Avaya Interactive Response (IR) are both shipped with an operating system from Sun Microsystems. Actions to be taken on those products are described below.

Recommended Actions:
Follow the recommended actions for each notification described below. This advisory will be updated as additional information becomes available.

Sun Advisory: Affected S/W Version Risk Comments or Recommended Actions
101933 CMS V9, 10, 11
R12, R13

IR - All
Low CMS V9, 10, 11, R12 R13 -
Patches have been tested, and are available from services. See recommended actions below.

IR - Patches have been tested, and are available from services. See recommended actions below.
102033 CMS V9, 10, 11
R12, R13

IR - All
Low CMS V9, 10, 11, R12 R13 -
Patches have been tested, and are available from services. See recommended actions below.

IR - Patches have been tested, and are available from services. See recommended actions below.
102087, 102108, 102124 All None No action is necessary. Solaris 10 is not used on IR or CMS.
102098, 102106, 102126,
102127, 102128, 102129
All None No action is necessary. StorEdge is not used on IR or CMS.

2. Recommended Actions:

Call Avaya Services at 1-800-242-2121 and open a ticket for the affected product. Advise the support technician of the Sun Alert ID (listed above) for the particular issue that needs remediation.

3. Additional Information:

Additional information may also be available via the Avaya support website and through your Avaya account representative. Please contact your Avaya product support representative, or dial 1-800-242-2121, with any questions.

4. Disclaimer:

ALL INFORMATION IS BELIEVED TO BE CORRECT AT THE TIME OF PUBLICATION AND IS PROVIDED "AS IS". AVAYA INC., ON BEHALF ITSELF AND ITS SUBSIDIARIES AND AFFILIATES (HEREINAFTER COLLECTIVELY REFERRED TO AS "AVAYA"), DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE AND FURTHERMORE, AVAYA MAKES NO REPRESENTATIONS OR WARRANTIES THAT THE STEPS RECOMMENDED WILL ELIMINATE SECURITY OR VIRUS THREATS TO CUSTOMERS' SYSTEMS. IN NO EVENT SHALL AVAYA BE LIABLE FOR ANY DAMAGES WHATSOEVER ARISING OUT OF OR IN CONNECTION WITH THE INFORMATION OR RECOMMENDED ACTIONS PROVIDED HEREIN, INCLUDING DIRECT, INDIRECT, CONSEQUENTIAL DAMAGES, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF AVAYA HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

THE INFORMATION PROVIDED HERE DOES NOT AFFECT THE SUPPORT AGREEMENTS IN PLACE FOR AVAYA PRODUCTS. SUPPORT FOR AVAYA PRODUCTS CONTINUES TO BE EXECUTED AS PER EXISTING AGREEMENTS WITH AVAYA.

5. Revision History:

V 1.0 - February 23, 2006 - Initial Statement issued.
V 2.0 - March 6, 2006 - Minor formatting changes, and clarified recommended actions.

Send information regarding any discovered security problems with Avaya products to either the contact noted in the product's documentation or [email protected].

© 2006 Avaya Inc. All Rights Reserved. All trademarks identified by the ® or ™ are registered trademarks or trademarks, respectively, of Avaya Inc. All other trademarks are the property of their respective owners.