|
|
>> Sun Solstice X.25 "/dev/xty" Local Denial of Service Vulnerability
|
Title : Sun Solstice X.25 "/dev/xty" Local Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-3087 CVE ID : CVE-2008-5009 CWE ID : CWE-399
Rated as : Low Risk 
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-11-10
|
A vulnerability has been identified in Sun Solstice X.25, which could be exploited by malicious users to cause a denial of service. This issue is caused by an unspecified error which may allow a local unprivileged attacker with read permission for "/dev/xty" to panic a system with multiple CPUs, creating a denial of service condition.
Affected Products
Sun Solstice X.25 version 9.2 for Solaris 8, 9, 10
Solution
Sun Solstice X.25 9.2 (SPARC / Solaris 8, 9 and 10) - Apply patch 108669-21 or later
Sun Solstice X.25 9.2 (x86 / Solaris 8, 9 and 10) - Apply patch 108670-21 or later
References
http://www.vupen.com/english/advisories/2008/3087 http://sunsolve.sun.com/search/document.do?assetkey=1-66-243106-1
Credits
Vulnerability reported by the vendor.
ChangeLog
2008-11-10 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|