PT-2009-4728 · Sun · Opensolaris+1

Published

2009-07-02

·

Updated

2009-07-15

·

CVE-2009-2297

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Sun Solaris versions 10, and OpenSolaris snv 90 through snv 108
Description The issue is related to an unspecified vulnerability in the udp subsystem in the kernel when Solaris Trusted Extensions is enabled. This allows remote attackers to cause a denial of service (panic) via unspecified vectors involving the crgetlabel function, which is related to a "TX panic." The problem exists due to a regression in earlier kernel patches.
Recommendations For Sun Solaris versions 10, and OpenSolaris snv 90 through snv 108, consider disabling Solaris Trusted Extensions as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-2297

Affected Products

Opensolaris
Sun Solaris