Security 10817 Published by

Flaw in Services for Unix 3.0 Interix SDK Could Allow Code Execution (Q329209)

All three vulnerabilities discussed in this bulletin involve the inclusion of the Sun [TM] Microsystems RPC library in Microsoft's Services for UNIX (SFU) 3.0 on the Interix SDK. Developers who created applications or utilities using the Sun RPC library from the Interix SDK need to evaluate three vulnerabilities.

Windows Services for UNIX (SFU) 3.0 provides a full range of cross- platform services to integrate Windows into existing UNIX environ- ments. In version 3.0, the Interix subsystem technology is built in so that Windows Services for UNIX 3.0 can provide platform inter- operability and application migration in one fully integrated and supported product from Microsoft.

Read more