• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • IBM Issues HiPER And Security Patches For V5R4

    September 21, 2015 Timothy Prickett Morgan

    Here is a weird one. Last week, IBM released PTF patches for OS/400 V5R4, also known as i5/OS 5.4, the venerable release of OS/400 that came out in February 2006 and that was withdrawn from marketing in May 2011 and had its standard Software Maintenance ended in September 2013. Extended maintenance is still running for those customers who pay for it, and will continue to do so until September 30, 2016.

    While this Program Support Extension (PSE) support does offer tech support for the V5R4 stack on Power Systems and earlier machines, it has always been my understanding that Big Blue does not generate new bug fixes outside of the normal Software Maintenance (SWMA) window. IBM does not do new feature development under extended support, but it does provide usage support, meaning helping you out when something goes wrong as you try to do stuff.

    Doug Bidwell, our intrepid PTF hunter, spotted the updates for V5R4 and has downloaded then and applied them to some customer machines that are still running V5R4 and they appear to work. The PTFs were put into the HIPER and Security PTF groups, HIPER being short for “High Impact” and “Pervasive” patches to the OS/400 and IBM i platform, and security being what you expect. As far as Bidwell can tell, the patches are exactly the same in both groups, and IBM has not issued a new cumulative release (CUME, in IBMspeak) of V5R4.

    Here are the PTF numbers so you can go hunting for them if you are still on V5R4:

    Here are the links to the two PTF groups:

    • IBM i Support: PSP: 540 Group HIPER
    • IBM i Support: PSP: 540 Group Security

    When you click through to those links, you will see that IBM actually did the updates on September 11 this year, and it updated the HIPER PTF group last on December 17, 2013 and the Security PTF group on January 29, 2013. The description of the issue is as follows from these documents: “ISC released an CVE-2015-5477, BIND did not handle TKEY queries correctly, and may cause BIND to exit. ISC released an CVE-2015-4620, over DNSSEC validation, which will affect V7R1~V7R2 release and can cause a security problem.”

    If you understand that, you need to spend more time outside. But seriously, ISC is short for the Internet Systems Consortium, and BIND is a popular open source implementation of the Domain Name Server (DNS) and is short for the Berkeley Internet Name Domain. The DNS is was converts the text names of a web address to an IP address with its four sets of three digit numbers. (We all thought it might have something to do with the binding of program elements during program compilations, but nothing that exciting.) Anyway, the bug fix for BIND, which is in the OS/400 V5R4 stack, relates to this security issue identified by CVE, allowing for denial of service attacks to be launched by remote hackers. This vulnerability was identified on July 10 of this year, and has been fixed in the Canonical Ubuntu Server, SUSE Linux Enterprise Server, Red Hat Enterprise Linux, and Debian variants of Linux.

    One warning from the patch: “After update to BIND 9, the V5R4 IBM i Navigator will not be compatible with the new version BIND server. The high version i Navigator (V6R1 or above) can be partially compatible with the BIND 9 on V5R4, it can be used to configure the existing instances, but when creating new instances, the generated configuration files will be still in BIND 8 format, and cannot work correctly with BIND 9.”

    The same fixes are in their equivalent groups for IBM i 6.1, 7.1, and 7.2.

    That sounds like a pain in the neck, but maybe not enough to just upgrade to IBM i 7.2. Which is probably a good idea, people.

    RELATED STORIES

    Big Blue Provides Extended Support For IBM i 6.1

    IBM Clarifies IBM i 6.1.1 And Support Withdrawal

    IBM i Marketplace Survey Fills In The Blanks

    Big Blue To Sunset IBM i 6.1 A Year From Now

    IBM i Upgrades Not All On The Same Path

    All Your IBM i Base Are Belong To Us

    IBM i Installed Base Dominated By Vintage Iron

    Big Blue Backs Off On IBM i Maintenance Price Hike

    Big Blue Jacks Software Maintenance Prices For IBM i

    IBM Sunsets i5/OS V5R4 Again–For Real This Time

    IBM i Technology Refreshes and PTFs: Be Careful

    The Carrot: i5/OS V5R4 Gets Execution Stay Until May

    The Stick: IBM Jacks Up i5/OS V5R4 Prices

    Reader Feedback on The Carrot: i5/OS V5R4 Gets Execution Stay Until May

    The i 7.1s Have It; i5/OS V5R4 Extended

    IBM Sunsets i5/OS V5R4, Kills Older 595 Iron

    Features Galore Inside i5/OS V5R4

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    BCD:  Modernizing IBM i Spool File Design and Distribution with New Formtastic 10. Webinar - Sept 24
    Four Hundred Monitor Calendar:  Latest info on national conferences, local events, & Webinars.
    System i Developer:  Session Grid Posted: RPG & DB2 Summit - Chicago, October 20-22

    Mad Dog 21/21: Land, Hope, And Glory Unifying Mobile and Web Development on IBM i

    Leave a Reply Cancel reply

Volume 25, Number 46 -- September 21, 2015
THIS ISSUE SPONSORED BY:

Profound Logic Software
Quadrant Software
HiT Software
Computer Keyes
LaserVault

Table of Contents

  • What Does IBM’s Embrace Of Apache Spark Mean To IBM i?
  • IBM Gearing Up For October Power Announcements
  • New RDi Ready For IBM i Developers
  • Mad Dog 21/21: Land, Hope, And Glory
  • IBM Issues HiPER And Security Patches For V5R4

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Brace Yourself: Another Power Systems Price Hike Coming May 1
  • Updates Announced for IBM i BRMS And SMTP Email Client
  • AI Will Be Front And Center At POWERUp 2026 Next Week
  • IBM i PTF Guide, Volume 28, Number 16
  • Spring IBM i Tech Refreshes Will Come A Bit Later This Year
  • You Are Much More Than Power Systems, And So Are We
  • Startup Seeks The “Golden Path” for IBM i Modernization
  • What Can IBM Do To Make The Future Power S1112 Mini System Compelling?
  • IBM i PTF Guide, Volume 28, Number 15
  • Bob 1.0 Users Bugged By Lack Of One Feature

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle