Updated: December 11, 2002
Affected
Sun confirms that a remote root exploit does affect the Sun/Cobalt RaQ4 platform if the SHP (Security Hardening Patch) patch was installed. Sun has released a Sun Alert which describes how to remove the SHP patch: http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fsalert/49377 The removal patch is available from: http://ftp.cobalt.sun.com/pub/packages/raq4/eng/RaQ4-en-Security-2.0.1-SHP_REM.pkg
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.