Oracle Solaris Patches and traceability to CVEs
I have been trying for some time to understand the Oracle Solaris patch process. I find it extremely difficult to understand whether or not certain Solaris packages are vulnerable. For example, Solaris Kerberos is based on MIT Kerberos. Therefore, it would be reasonable to assume that a vulnerability within MIT Kerberos may impact Solaris Kerberos (e.g. CVE-2011-0065). However, when I try to search for CVE-2011-0065 I find absolutely nothing. Looking at the MIT kerberos website I see that this CVE is included in version 1.8.4. The same can be said for SSL, Mozilla, and a host of other opensource software included in Solaris. I
2