PT-2009-3434 · Sun · Sun Solaris+1
Published
2009-03-06
·
Updated
2018-10-30
·
CVE-2009-0838
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 10
OpenSolaris versions snv 88 through snv 102
Description
The issue is related to the crypto pseudo device driver, which does not properly free memory. This can be exploited by local users to cause a denial of service, resulting in a system panic. The problem is associated with the
vmem hash delete function.Recommendations
For Sun Solaris version 10, update to a version that properly frees memory in the crypto pseudo device driver.
For OpenSolaris versions snv 88 through snv 102, update to a version that properly frees memory in the crypto pseudo device driver.
As a temporary workaround, consider restricting access to the crypto pseudo device driver to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensolaris
Sun Solaris