PT-2009-5215 · Sun · Opensolaris+1

Published

2009-08-19

·

Updated

2025-01-21

·

CVE-2009-2857

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Sun Solaris versions 8 through 10 OpenSolaris versions prior to snv 103
Description The issue arises from improper handling of interaction between the filesystem and virtual-memory implementations. This allows local users to cause a denial of service, resulting in a deadlock and system halt, by performing specific operations on the same file, involving mmap and write operations.
Recommendations For Sun Solaris versions 8 through 10, consider applying configuration changes to restrict access to sensitive files and minimize the risk of exploitation. For OpenSolaris versions prior to snv 103, update to a version after snv 103 to resolve the issue. As a temporary workaround, consider restricting the use of mmap and write operations on the same file to minimize the risk of deadlock and system halt.

Fix

Improper Locking

Weakness Enumeration

Related Identifiers

CVE-2009-2857

Affected Products

Opensolaris
Sun Solaris