PT-2009-4728 · Sun · Opensolaris+1
Published
2009-07-02
·
Updated
2009-07-15
·
CVE-2009-2297
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 10, and OpenSolaris snv 90 through snv 108
Description
The issue is related to an unspecified vulnerability in the udp subsystem in the kernel when Solaris Trusted Extensions is enabled. This allows remote attackers to cause a denial of service (panic) via unspecified vectors involving the
crgetlabel function, which is related to a "TX panic." The problem exists due to a regression in earlier kernel patches.Recommendations
For Sun Solaris versions 10, and OpenSolaris snv 90 through snv 108, consider disabling Solaris Trusted Extensions as a temporary workaround to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opensolaris
Sun Solaris