PT-2018-1116 · Oracle · Solaris

Publicado

2018-01-16

·

Atualizado

2018-01-26

·

CVE-2018-2710

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Oracle Sun Systems Products Suite (subcomponent: Kernel) version 10
Description The issue is related to a vulnerability in the Kernel component of the Solaris operating system, which can be exploited by an unauthenticated attacker with network access via ICMP. This vulnerability can result in the ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. The exploitation of this vulnerability is considered easily exploitable.
Recommendations For version 10, apply the necessary security patches to fix the vulnerability in the Kernel component. As a temporary workaround, consider restricting access to ICMP protocol to minimize the risk of exploitation.

Correção

Improperly Implemented Security Check for Standard

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00533
CVE-2018-2710

Produtos afetados

Solaris