Patch Name: PHCO_5295 Patch Description: s700 9.09/9.09+ To protect against malicious misuse of cron Creation Date: 95/03/30 Post Date: 95/04/18 Hardware Platforms - OS Releases: s700: 9.09+ 9.09 Products: N/A Filesets: CMDS-MIN Automatic Reboot?: No Status: General Release Critical: No Path Name: /hp-ux_patches/s700/9.X/PHCO_5295 Symptoms: PHCO_5295: Possible malicious misuse of cron. Defect Description: PHCO_5295: Possible malicious misuse of cron. SR: 4701285411 Patch Files: /etc/cron what(1) Output: /etc/cron: $Revision: 70.19.4.9 $ $Revision: 70.8.1.3.2.1 $ cron.c $Revision: 70.8.1.3.2.1 $ $Date: 95/03/30 10:37:28 $ PATCH_9.09(+) (PHCO_5295) PATCH_ 908 (PHCO_5414) sum(1) Output: 22662 96 /etc/cron Patch Conflicts: None Patch Dependencies: None Hardware Dependencies: None Other Dependencies: None Supersedes: None Equivalent Patches: None Patch Package Size: 110 Kbytes Installation Instructions: Please review all instructions and the Hewlett-Packard SupportLine User Guide or your Hewlett-Packard support terms and conditions for precautions, scope of license, restrictions, and, limitation of liability and warranties, before installing this patch. ------------------------------------------------------------ 1. Back up your system before installing a patch. 2. Copy the patch to your /tmp directory and unshar it: cd /tmp cp patch_source/PHCO_5295 . sh PHCO_5295 3. Become root and run update: /etc/update 4. Use the cursor keys to select "Change Source or Destination ->" and press [Return]. 5. Select "From Tape Device to Local System ..." in the Change window and 6. Change "Source: /dev/rmt/0m" to "Source: /tmp/PHCO_5295.updt" 7. Press "Done" (f4). 8. Follow the standard directions for update. Update moves the original software to /system/PHCO_5295/orig. Keep this file to recover from any potential problems. You should move the .text file to /system/PHCO_5295 for future reference. To put this patch on a magnetic tape and update from the tape drive, use dd: dd if=PHCO_5295.updt of=/dev/rmt/0m bs=2048 Special Installation Instructions: None