PT-2007-3789 · Sun · Sun Solaris

Published

2007-05-02

·

Updated

2018-10-30

·

CVE-2007-2465

CVSS v2.0

4.7

Medium

VectorAV:L/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Sun Solaris version 9
Description The issue allows local users to cause a denial of service, resulting in a system panic, when Solaris Auditing (BSM) is enabled for certain audit classes, such as file read, write, attribute modify, create, or delete. The exact vectors are unknown, but it may be related to the audit savepath function.
Recommendations For Sun Solaris version 9, consider disabling Solaris Auditing (BSM) for the affected audit classes as a temporary workaround to minimize the risk of denial of service attacks. Restrict access to the audit savepath function until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2465

Affected Products

Sun Solaris