PT-2008-6741 · Oracle · Opensolaris+1

Tobias Klein

·

Publicado

2008-12-19

·

Atualizado

2018-10-11

·

CVE-2008-5689

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Solaris versions 10 and OpenSolaris snv 01 through snv 76
Description The issue allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCGTUNPARAM IOCTL request. This request triggers a NULL pointer dereference in the tun in IP Tunnel component.
Recommendations For Solaris versions 10 and OpenSolaris snv 01 through snv 76, consider restricting access to the tun in IP Tunnel component to minimize the risk of exploitation. As a temporary workaround, avoid using the SIOCGTUNPARAM IOCTL request until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5689

Produtos afetados

Opensolaris
Solaris