PT-2008-5833 · Sun · Sun Solaris
Federico L. Bossi Bonin
·
Publicado
2008-10-20
·
Atualizado
2018-10-30
·
CVE-2008-4619
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Solaris version 9
Description
The issue allows remote attackers to cause a denial of service, resulting in a daemon crash, by sending a crafted request to a specific procedure in the RPC subsystem. This is related to the XDR DECODE operation and the taddr2uaddr function.
Recommendations
For Sun Solaris version 9, consider restricting access to the RPC subsystem to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the rpcbind service may help prevent the daemon crash.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sun Solaris