PT-2009-3134 · Sun · Sun Solaris+1
Published
2009-02-09
·
Updated
2017-09-29
·
CVE-2009-0480
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 8 through 10
OpenSolaris versions prior to snv 82
Description
The issue is related to the IP implementation, which improperly allocates minor numbers for sockets. This can be exploited by local users to cause a denial of service, resulting in 32-bit application failure and login outage, by opening a large number of sockets.
Recommendations
For Sun Solaris versions 8 through 10, consider restricting socket usage to prevent denial of service.
For OpenSolaris versions prior to snv 82, consider upgrading to a version after snv 82 to resolve the issue.
At the moment, there is no information about additional mitigation measures for these versions.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensolaris
Sun Solaris