PT-2009-3466 · Sun · Sun Solaris+1
Published
2009-03-12
·
Updated
2009-04-02
·
CVE-2009-0874
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 8 through 10
OpenSolaris versions prior to snv 94
Description
The issue affects the Doors subsystem in the kernel, allowing local users to cause a denial of service, bypass file permissions, or gain kernel-context privileges. This can be achieved through vectors including an argument handling deadlock in a door server and watchpoint problems in the
door call function.Recommendations
For Sun Solaris versions 8 through 10, consider applying a patch or fix to address the argument handling deadlock and watchpoint problems in the door call function.
For OpenSolaris versions prior to snv 94, update to a version after snv 94 to resolve the issue.
As a temporary workaround, consider restricting access to the Doors subsystem to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensolaris
Sun Solaris