<html>
<head>
<meta content="text/html; charset=ISO-8859-15"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
Thanks for the further investigation Martin! I'll follow up.<br>
<br>
There is nothing to prevent those patches being added to a system
installed with s10u11, so it would seem prudent to add the Security
fixes indicated below in the case where the patch pkgs are installed
systems. (I've provided details of the pkgs delivered in the 2
patches that you've pointed out below for ease of reference.)<br>
<br>
As a general rule of thumb, it is always advisable to apply the
latest Recommended Patchset after installing/upgrading to the latest
Solaris Update to get any fixes relesed after the Solaris Update (or
in this case not delivered as part of the update itself).<br>
<br>
Best,<br>
-Don<br>
<br>
On 02/13/13 07:12, Martin Paul wrote:
<blockquote cite="mid:511B3CE4.8090304@univie.ac.at" type="cite">Hi
Don,
<br>
<br>
Am 12.02.2013 20:00, schrieb Don O'Malley:
<br>
<blockquote type="cite">I'll take a look into this one and get
back to you.
<br>
</blockquote>
<br>
Thanks for the information you already provided. Apart from that,
it might be worth to at least take a look at these two patches:
<br>
<br>
<blockquote type="cite">
<blockquote type="cite">Patch IR CR RSB Age Synopsis
<br>
------ -- - -- --- ---
-------------------------------------------------------
<br>
119213 26 < 27 RS- 369 NSS_NSPR_JSS 3.13.1: NSPR 4.8.9 /
NSS 3.13.1 / JSS 4.3.2
<br>
149453 -- < 02 RS- 133 SunOS 5.10: CCR Update
<br>
</blockquote>
</blockquote>
<br>
Both of them are "S"ecurity patches, and both of them contain
actual security fixes (which Oracle nowadays often paraphrases as
"problem with X"):
<br>
<br>
-- 119213-27:
<br>
<br>
13341290 DIS-TRUST DIGINOTAR ROOT CERTIFICATE
<br>
13341314 (CVE-2011-3389) RIZZO/DUONG CHOSEN PLAINTEXT ATTACK
(BEAST) ON SSL/TLS 1.0
<br>
</blockquote>
PKG=SUNWjss<br>
ARCH=sparc<br>
VERSION=4.0,REV=2004.11.05.02.31<br>
<br>
PKG=SUNWpr<br>
ARCH=sparc<br>
VERSION=4.5.1,REV=2004.11.05.02.30<br>
<br>
PKG=SUNWprd<br>
ARCH=sparc<br>
VERSION=4.5.1,REV=2004.11.05.02.30<br>
<br>
PKG=SUNWtls<br>
ARCH=sparc<br>
VERSION=3.9.5,REV=2005.01.14.17.27<br>
<br>
PKG=SUNWtlsd<br>
ARCH=sparc<br>
VERSION=3.9.5,REV=2005.01.14.17.27<br>
<br>
PKG=SUNWtlsu<br>
ARCH=sparc<br>
VERSION=3.9.5,REV=2005.01.14.17.27<br>
<br>
<blockquote cite="mid:511B3CE4.8090304@univie.ac.at" type="cite">
<br>
-- 149453-02
<br>
<br>
7194816 problem with smpatch / updatemanager
<br>
6914463 problem with smpatch / updatemanager
<br>
</blockquote>
PKG=SUNWccccr<br>
ARCH=sparc<br>
VERSION=001.000.000<br>
<br>
<blockquote cite="mid:511B3CE4.8090304@univie.ac.at" type="cite">
<br>
It's kind of strange to get a Solaris release in Feb 2013 with
existing security fixes from up to a year ago not being fixed out
of the box.
<br>
<br>
Martin.
<br>
<br>
</blockquote>
<br>
<div class="moz-signature">-- <br>
<a href="http://www.oracle.com/"> <img
src="cid:part1.00070708.09080608@oracle.com" name="graphics1"
align="bottom" border="0"></a> <br>
<font face="Verdana, sans-serif" size="2"><b>Don O'Malley</b></font><br>
<font face="Verdana, sans-serif" size="2" color="#666666">
Manager, Software Maintenance Engineering<br>
Revenue Product Engineering | Solaris | Hardware <br>
Block C, East Point Business Park, Dublin 3, Ireland<br>
Phone: +353 1 8033883 <br>
Team Alias: <a href="mailto:rpe_sme_ww_grp@oracle.com">rpe_sme_ww_grp@oracle.com</a><br>
</font> </div>
</body>
</html>