PT-2009-4996 · Sun · Opensolaris+1
Published
2009-07-27
·
Updated
2009-07-27
·
CVE-2009-2596
CVSS v2.0
4.7
Medium
| Vector | AV:L/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 9 and 10
OpenSolaris versions prior to snv 121
Description
The issue is related to an unspecified vulnerability in the Solaris Auditing subsystem. It affects systems when extended file attributes are used, allowing local users to cause a denial of service (panic) through vectors related to
fad aupath structure members.Recommendations
For Sun Solaris versions 9 and 10, update to a version that includes the fix for this issue.
For OpenSolaris versions prior to snv 121, update to a version snv 121 or later.
As a temporary workaround, consider restricting the use of extended file attributes until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opensolaris
Sun Solaris