PT-2018-1116 · Oracle · Solaris
Publicado
2018-01-16
·
Atualizado
2018-01-26
·
CVE-2018-2710
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Sun Systems Products Suite (subcomponent: Kernel) version 10
Description
The issue is related to a vulnerability in the Kernel component of the Solaris operating system, which can be exploited by an unauthenticated attacker with network access via ICMP. This vulnerability can result in the ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. The exploitation of this vulnerability is considered easily exploitable.
Recommendations
For version 10, apply the necessary security patches to fix the vulnerability in the Kernel component. As a temporary workaround, consider restricting access to ICMP protocol to minimize the risk of exploitation.
Correção
Improperly Implemented Security Check for Standard
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Solaris