Cobalt Updates
Sun Cobalt RaQ2

Downloads MUST be applied from the bottom of the page to the top, as they must be applied in chronlogical order. Application of these patches in improper order will likely result in problems with the Sun Cobalt™ product.
ALWAYS MAKE A GOOD BACKUP BEFORE DOING ANY UPDATE!!!

NOTE: All software is on a "per motherboard" licence and the packages are installed for you to insure the best installation possible. All systems are first checked for fitness before anything is installed... Updates and Reinstallations incurr my minimum charge ($50.00usd)... You will be required to Enter your IP and admin password when prompted by paypal or contact me. All packages are designed to install on a clean system. All systems should be in good running order before package installation. "User group" and other messy servers may require additional charges.


The BIND updates are un-tested for now. I just don't have a RaQ2 online anymore to do DNS testing.


The BIND updates are un-tested for now. I just don't have a RaQ2 online anymore to do DNS testing.


The BIND update is un-tested for now. I just don't have a RaQ2 online anymore to do DNS testing.

BIND Security Update

HTTP RaQ2-BIND-8.4.7-Z1-Built-by-Zeffie.com.pkg Posted:May 17, 2006
FTP Point your FTP client to ftp://www.zeffie.com/ Size: 8,602,900

This updates the "BIND", "Named", or "DNS Server" software and closes Multiple Security Issues.

Pre-Requisites:
(You should have all done all the updates!)

Reboot Required: no

MD5 Check Sum: 1addcca71e9862fa55010673737bda71


IMAP Security Update/Upgrade

HTTP RaQ2-IMAP-2002d-12.Z3-Built-by-Zeffie.com.pkg Posted:May 17, 2006
FTP Point your FTP client to ftp://www.zeffie.com/ Size: 3,686,559

This upgrades the IMAP software and closes Multiple Security Issues...

Pre-Requisites:
(You should have all done all the updates!)

Reboot Required: no

MD5 Check Sum: b202cee5b91f4e6e1906c48d3ccac714


OpenSSH Client and Server Software.

HTTP RaQ2-Openssh-STATIC-4.3p1-1.Z1-Built-by-Zeffie.com.pkg Posted:May 17, 2006
FTP Point your FTP client to ftp://www.zeffie.com/ Size: 2,617,071

This adds OpenSSL to the base system.

Pre-Requisites:
OpenSSL

Reboot Required: no

MD5 Check Sum: 79ea94627516df77a0a78c3ce51a9010


Qpopper Upgrade/Update

HTTP RaQ2-Qpopper-4.0.8-C5.Z1-Built-by-Zeffie.com.pkg Posted:May 17, 2006
FTP Point your FTP client to ftp://www.zeffie.com/ Size: 382,876

This Upgrades the pop3 server program "Qpopper" and closes Multiple Security Issues"

Pre-Requisites:
(You should have all done all the updates!)

Reboot Required: no

MD5 Check Sum: 73f96906bf416d0b7a89f036c5f9f85f


Sendmail Security Update

HTTP RaQ2-Sendmail-8.9.3-C7.Z1-Built-by-Zeffie.com.pkg Posted:May 17, 2006
FTP Point your FTP client to ftp://www.zeffie.com/ Size: 919,174

This Updates Sendmail and closes Multiple Security Issues...

Pre-Requisites:
(You should have all done all the updates!)

Reboot Required: yes

MD5 Check Sum: 9182eb7b4e5e8928a5188aab7f132ae8


Telnet Security Update

HTTP RaQ2-Telnet-0.17-19.Z1-Built-by-Zeffie.com.pkg Posted:May 17, 2006
FTP Point your FTP client to ftp://www.zeffie.com/ Size: 48,124

This Updates the Telnet software and closes Multiple Security Issues... (Even if you don't use it you should do this update to keep both the server and the client software current...)

Pre-Requisites:
(You should have all done all the updates!)

Reboot Required: no

MD5 Check Sum: 5c81ab37a6387aa85736f3ec012341e3


Vim Security Update

HTTP RaQ2-Vim-6.3.046-0.30E.4.Z1-Built-by-Zeffie.com.pkg Posted:May 17, 2006
FTP Point your FTP client to ftp://www.zeffie.com/ Size: 5,261,156

This Updates the vim or vi editor software and closes Multiple Security Issues...

Pre-Requisites:
(You should have all done all the updates!)

Reboot Required: no

MD5 Check Sum: 5e815cb436c666f01a5a6ca007badeb6


OpenSSL Upgrade

HTTP RaQ2-OpenSSL-0.9.7a-43.4.Z1-Built-by-Zeffie.com.pkg Posted:May 17, 2006
FTP Point your FTP client to ftp://www.zeffie.com/ Size: 2,630,610

This Upgrades the RaQ2 to include OpenSSL which is required by other Updates and Upgrades...

Pre-Requisites:
(You should have all done all the updates!)

Reboot Required: no

MD5 Check Sum: a19e41be377208dc6fb381c7fc050a44



NOTICE

The Official Sun Cobalt Updates End Here!

All Updates from this point are created by me, Zeffie of Zeffie.com...

Please note that you are using these updates at your own risk and I do not provide free support for them. If you have problems you should try installing the pkgs from the command line and watch for any error messages...

These pkg files also represent a basic change in the way updates have been made in the past... While most software was "patched" in the past, it will be my goal to build updated pkgs equivalent to the now Current RedHat Enterprise 3 or best... I will be doing my very best to avoid building "patched" versions of old software however in some places there is no choice.


CGIWrap Update 4.0.1

HTTP RaQ2-All-Security-4.0.1-14997.pkg Posted: August 27, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 43,254

This package contains an updated CGIWrap that addresses a security issue recently discovered. For more information, please see: http://online.securityfocus.com/bid/3084

Reboot Required: No

MD5 Check Sum: 4ec44da70d6087ee1696b98c73a3098e


Apache Update 4.0.1

HTTP RaQ2-All-Security-4.0.1-15417.pkg Posted: June 28, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 918,820

This package contains an updated Apache HTTP Server that addresses a security issue recently discovered. For more information, please see http://httpd.apache.org/info/security_bulletin_20020617.txt

Note to Brosoft SSL users:

Please refer to Brosoft's web site for the latest version of this update. http://www.brosoft.net/en/os_update.html

Reboot Required: Yes

MD5 Check Sum: 74ccd9289fee962157d864d9bcacb203


TCPDUMP Update 4.0.1

HTTP RaQ2-All-Security-4.0.1-14559.pkg Posted: June 27, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 501,755

This patch replaces the TCPDUMP network analysis tool with a new version. This version of TCPDUMP contains security fixes for issues that were found in prior releases of TCPDUMP for the Sun Cobalt Server Appliance.

Reboot Required: No

MD5 Check Sum: ceca89ca4e9153a16df7041feb6735c3


Security Bundle Update 4.0.1

HTTP RaQ2-All-Security-4.0.1-13323.pkg Posted: June 18, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 10,473,104

This package contains security updates for a varity of programs included on the Sun Cobalt Qube 2 appliance. The following packages have been upgraded:

  • ProFTPD 1.2.4
  • zlib 1.1.3-25.7c1r2
  • pine 4.44-C1
  • binutils 2.8.1-1C2r2
  • CVS 1.10.2-1c1r2
  • GCC 2.7.2-c3r3
  • sed 2.05-7c1r2
Reboot Required: No

MD5 Check Sum: 9286181dd4d868d7ab5c3c454d76a56e


glibc Update 4.0.1

HTTP RaQ2-All-Security-4.0.1-13453.pkg Posted: March 13, 2002
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 8,739,982

This updates the version of glibc to fix a known vulnerability with file globbing functionality. See the following link for details: http://online.securityfocus.com/bid/3707

MD5 Check Sum: 4f2ece611d5480d1cc3c6dd0b85f81c1

Reboot Required: Yes


Analog Patch Update 4.0.1

HTTP RaQ2-All-Security-4.0.1-9769.pkg Posted: November 19, 2001
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 546,484

After Installing Update 4.0, analog reports may not be generated correctly. Web statistic report options will be greyed out as a result. This patch fixes this issue.

Prerequisites: Sun Cobalt RaQ 2 OS Update 4.0

MD5 Check Sum: 824b5e402a1029d80b4e9d38ea3ab391

Reboot Required: No


telnetd Update 4.0.1

HTTP RaQ2-All-Security-4.0.1-10750.pkg Posted: August 22, 2001
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 78,274

This security patch addresses an issue found in the telnet daemon, where a remote attacker is able to gain access to server appliances if telnet is enabled. Information regarding this update can be found at CERT Coordination Center's website. The URL is: http://www.cert.org/advisories/CA-2001-21.html.

MD5 Check Sum: 0dc276ebe44f1d880ca69d31ba8affc4


Special Characters Update 4.0.1

HTTP RaQ2-All-System-4.0.1-9925.pkg Posted: July 23, 2001
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 7,020

System problems may occur when using special characters when adding a new username or a user’s full name. This update enables the use of special characters such as “.” in a username and “’” in user’s full names

MD5 Check Sum: dd2eb15c370f461fcfda2bd8fe435b6c


OS Update 4.0

HTTP RaQ2-en-OSUpdate-4.0.pkg Posted: June 29, 2001
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 9,593,369

Reboot required: Yes

MD5 Check Sum: f78b58fca4995ed583fcecfbdfc04449

Prerequisites:

RaQ2-en-Update-OS-3.0
RaQ2-All-Security-3.0.1-8061

Obsoletes These Previous Updates:

RaQ2-All-Security-3.0.1-6682
RaQ2-All-Security-3.0.1-6750
RaQ2-All-System-3.0.1-7362
RaQ2-All-Security-3.0.1-6449
RaQ2-All-Security-3.0.1-8008
RaQ2-All-Security-3.0.1-8164
RaQ2-All-Security-3.0.1-8577
RaQ2-All-Security-3.0.1-8747
RaQ2-All-Security-3.0.1-8762
RaQ2-All-Security-3.0.1-9353
RaQ2-All-Security-3.0.1-8532
RaQ2-All-Security-3.0.1-9531
RaQ2-All-Security-3.0.1-9077
RaQ2-All-Security-3.0.1-9648
RaQ2-All-Security-3.0.2-9769
RaQ2-All-Security-3.0.1-9878
RaQ2-All-Security-3.0.1-10108
RaQ2-All-Security-3.0.1-10198

Cumulative List of Bug Fixes and Feature Changes:

  • Modified confusing Active Monitor error messages.
  • Added 127.0.0.1/localhost as an acceptable combination for DNS
  • Email to mailing lists would bounce to admin if it contained any Majordomo commands in the first 10 lines
  • NTP server was unable to be set up in some network topologies.
  • Email sent to majordomo@domain.com was bounced in certain circumstances
  • "Delete Domain" button now displays properly in Japanese text (Japanese Only)

Note to Users running Sun Cobalt RaQ 2 software on RaQ 1 hardware:

There was an issue with Update 3.0 which caused problems for users with this special build.
Before installing RaQ2-en-Update-OS-3.0 and RaQ2-en-OSUpdate-4.0
Please install the following package: RaQ2-All-System-2.0.1-8374.pkg

MD5 Check Sum: a4a203e9e7bec29bf22ea74627bb1e0f


glibc Update 3.0.1

HTTP RaQ2-All-Security-3.0.1-8061.pkg Posted: November 29, 2000
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 8,747,185

This updates the version of glibc. Prior to this update it was possible for local users to gain root access.


OS Update 3.0

HTTP RaQ2-en-Update-OS-3.0.pkg Posted: July 31, 2000
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 8,211,371

Installation Notes:

Update OS 2.0 is required before installing Update OS 3.0.

Obsoletes These Previous Updates:

RaQ2-Update-MFG-2.1
RaQ2-Security 2.0
RaQ2-Security 2.1
RaQ2-Security 2.3
RaQ2-Security 2.7
RaQ2-Security 2.8
RaQ2-Security 2.9
RaQ2-Security 2.91
RaQ2-Security 2.92
RaQ2-Security 2.93
RaQ2-Security 2.94
RaQ2-Security 2.95
RaQ2-Security 2.96
RaQ2-Security 2.97
RaQ2-All-System-2.98-6168
All-Kernel-MIPS Update 1.0

Cumulative List of Bug Fixes and Feature Changes:

Operating System and User Interface

  • Updated kernel version to improve network stability under load conditions. Now also recognizes multiple SCSI Logical Unit Numbers.
  • The log file /var/log/analog.dns was not being rotated properly in the log rotation process. This could accidentally lead to a diskfull error condition.
  • "The administrator was improperly prevented from modifying a user's settings when any mailing lists beginning with 1, 3 or 4 werecreated on the system."
  • The site user modification routine improperly allowed any site administrator to change the password of the main administrator.
  • The site user addition routine improperly allowed any site administrator to modify the information of another virtual site.
  • User interface now allows two successive dashes in a domain name.
  • Changing the IP address of a main site to match the IP address of an already existing virtual site improperly caused a loss ofnetwork services.
  • The system improperly ignored error messages which occurred while changing IP addresses.
  • Attempting to clear the value of the secondary domain name server at the same time as entering a value for the primary domain nameserver would occasionally fail to clear the value of the secondary domain name server.
  • Users are no longer allowed to improperly create a virtual site with the same IP address as the IP address of their default gateway.
  • The cron program was updated to fix a potential buffer overflow security problem that might allow a user to gain root privileges.
  • The syslog server was updated to fix a potential denial of service security problem.
  • The su command was updated to fix a potential security problem due to the absence of any logging of failed attempts to gain full root access.
E-Mail and Mailing Lists
  • Increased the maximum number of allowable POP connections per minute from 40 to 200.
  • The POP server was upgraded to fix a potential problem where a user would be incorrectly prevented from successfully downloading e-mail messages using a POP connection. This would typically occur when a user's e-mail spool file exceeded more than half of the user's total disk space quota.
  • A user could improperly be created with the same name as an already existing mailing list or e-mail alias, thereby improperlyintercepting e-mail messages.
  • A user on a virtual site improperly received e-mail destined for a user which does not exist on another virtual site if the e-mailis addressed to the same user name. That is to say, a message sent to an invalid user@virtual.site.two.com was improperly sent to the valid user@virtual.site.one.com instead of being bounced. Now, invalid messages will be bounced for all newly created virtual sites. For all existing virtual sites, temporarily changing the host name of the existing virtual sites and then changing them back to their original host name will fix the problem.
  • Fixed a problem where the e-mail aliases of every user in every virtual site were improperly deleted if more than one person made changes to e-mail aliases exactly at the same time.
  • Repeatedly toggling the ""Accept EMail For Domain"" site setting for a virtual site often improperly stopped the mail server from responding.
  • The e-mail server was updated to fix a potential security problem due to the possibility of a user corrupting the aliases database and thereby stopping service.
  • Fixed a security issue whereby a malicious user with shell access could use the vacation message field to compromise the system.
  • The vacation message of a user was not deleted properly when the user was deleted.
  • Changed formatting of date and time within vacation auto responder messages, in order to conform to standards.
  • The mailing list program was updated to fix a potential security problem that might allow a user to gain higher privileges.
  • All mailing lists were created with a default password, which posed a potential security problem. Now, all mailing lists have a randomly generated password for both the list owner and the list moderator.
  • The system no longer allows any member of a mailing list to display all the other members.
  • The system no longer allows any user to display all the mailing lists on the server appliance.
Web and FrontPage Extensions
  • The web server was updated to fix a potential denial of service security problem.
  • The web service normally allowed anybody accessing a web site to view a "".htaccess"" file or "".htpasswd"" file. The web service no longer allows any files that begin with "".ht"" from being transmitted via the web.
  • The cgi wrapper program was updated to disallow any cgi scripts from running unless its ownership is changed from httpd to a specific user. This specifically affects all scripts uploaded via FrontPage. This closes a security problem which allowed a malicious site administrator to modify datain another virtual site.
  • The ownership of all virtual site directories and their contents were changed from httpd to nobody. This closes a security problem which allowed a malicious site administrator to bypass the cgi wrapper program and then modify data in another virtual site.
  • FrontPage configuration errors are now logged in /var/cobalt/adm.log instead of being discarded.
  • Disk quotas were improperly calculated for sites using FrontPage Server Extensions.
FTP and File Sharing
  • The FTP server could improperly deny site administrators access to any directories above their home directories, thereby denying access to their virtual site web directory. This typically occurs for the site administrator group when the total length of the user names in the group are greater than 1024 characters in length.
  • If the IP address of a virtual site with anonymous FTP access enabled was changed to match the IP address of another virtual site with anonymous FTP access enabled, user interface inconsistencies would occur. Anonymous FTP access is now first disabled on the virtual site that is to be changed.
Backup and Restore
  • The backup routine improperly allowed anyone to run a complete or configuration only backup routine, thereby allowing access to some sensitive configuration files. The scheduled backup routine sometimes improperly used text transfer mode instead of using binary transfer mode for all FTP transfers, thereby irretrievable corrupting some backups.
  • The backup routine improperly allowed anyone to run a group backup routine, thereby potentially allowing access to other user's files.
  • Scheduled backups could not be created if share names had dashes in them.
  • Backups of server configuration files did not always properly include all necessary server configuration files.
  • Backups did not properly handle filenames with apostrophes in them.
  • Doing a selective restore of a backup file incorrectly left behind a temporary copy in /home/tmp instead of deleting it properly.
Domain Name Service
  • The domain name server was updated to fix several potential denial of service security problems.
Miscellaneous
  • Internationalized the textual description for two button icons on the virtual site management screen. (Japanese Only)
  • The user interface would incorrectly fail to detect a network time server that was operational in cases where ping requests were being blocked by a firewall.
  • Fixed minor user interface typos in the help text description for the network time server.
  • Fixes a problem where the Cobalt Logo light on the front panel incorrectly turns off under heavy use.
Installation Notes:

Customers with large number of Frontpage sites should install this patch in the following manner:

  1. Download the package to your local machine.
  2. Ftp the file onto the RaQ2.
    > ftp
    Connected to .
    220 ProFTPD 1.2.0pre9 Server (ProFTPD) [raq2.cobalt.com]
    User (raq2.cobalt.com:(none)): admin
    331 Password required for admin.
    Password:
    230 User admin logged in.
    ftp> cd /tmp
    250 CWD command successful.
    ftp> put RaQ2-en-Update-OS-3.0.pkg
  3. telnet into the RaQ2 and AS ROOT run the following command
    [root /tmp]# /usr/local/sbin/cobalt_upgrade
    /tmp/RaQ2-en-Update-OS-3.0.pkg
    ......
    201 Installation successful.
    [root /tmp]#
Note to Brosoft SSL users:

Please refer to Brosoft's web site for the latest version of this update. http://www.brosoft.net/en/os_update.html


OS Update 2.0

HTTP RaQ2-Update-OS-2.0.pkg Posted: October 10, 1999
FTP Point your FTP client to ftp://ftp.cobalt.sun.com Size: 14,910,288

This update contains several security updates and Frontpage 2000 Server Extensions.

  • Fix: Update contains all fixes in RaQ2-Security-1.0.pkg.
  • Fix: Update contains all fixes in RaQ2-Security-1.2.pkg.
  • Fix: Update contains all fixes in RaQ2-Security-1.4.pkg.
  • Upgrade: FrontPage 98 Server Extensions have been upgraded to FrontPage 2000 Server extensions.
  • Fix: Anonymous FTP would get disabled if another named based virtual hosts was added to the base IP address.
  • Upgrade: Legato now has a Parameters Section once enabled. It now starts portmapper and passes the Legato server name to the service.

I Accecpt...
Pay me securely with your Visa, MasterCard, Discover, or American Express card through PayPal! Visa ,MasterCard, Discover, and American Express
Cobalt Partner

Check me out on the Wayback Machine
This entire site is Copyright 2021 by Electronic Consultants Incorporated.