PT-2009-3434 · Sun · Sun Solaris+1

Published

2009-03-06

·

Updated

2018-10-30

·

CVE-2009-0838

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Sun Solaris versions 10 OpenSolaris versions snv 88 through snv 102
Description The issue is related to the crypto pseudo device driver, which does not properly free memory. This can be exploited by local users to cause a denial of service, resulting in a system panic. The problem is associated with the vmem hash delete function.
Recommendations For Sun Solaris version 10, update to a version that properly frees memory in the crypto pseudo device driver. For OpenSolaris versions snv 88 through snv 102, update to a version that properly frees memory in the crypto pseudo device driver. As a temporary workaround, consider restricting access to the crypto pseudo device driver to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0838

Affected Products

Opensolaris
Sun Solaris