Greetings,
Regarding the CIAC G-09 bulletin about the sendmail/syslog vulnerabilities
that were reported earlier in CERT ADVISORY CA-95:13, I went to
http://www.service.digital.com's patch services and found the ECO for DU
3.2C.  However, it contains a note that the ECO is on 'engineering hold'. 
Does anyone have any info on whether this will become available? 
Also, the CIAC bulletin includes instructions for using adb to 
write a null byte to the EXPN and VRFY commands.   Is adb available in
DU 3.2C?   Is there a layered product I need to install?   Or can 
anyone tell me the gdb commands to write a null byte to a particular
decimal address?
Regards,
Patrick O'Brien
>From http://www.service.digital.com:8031/ :
This    ECO contains the following files:
     ssrt0359_osf1032c.README
     ssrt0359_osf1032c.CHKSUM
     ssrt0359_osf1032c.tar
     ssrt0359_osf1032c.CVRLET_
Copyright (c) Digital Equipment Corporation 1995.  All rights reserved.
    ************************ NOTE *************************
    *                                                     *
    * Engineering is currently researching a problem with *
    * this ECO and requested that it be placed on         *
    * engineering hold.                                   *
    *                                                     *
    *******************************************************
Received on Mon Feb 05 1996 - 17:13:16 NZDT