PT-2009-5215 · Sun · Opensolaris+1
Published
2009-08-19
·
Updated
2025-01-21
·
CVE-2009-2857
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 8 through 10
OpenSolaris versions prior to snv 103
Description
The issue arises from improper handling of interaction between the filesystem and virtual-memory implementations. This allows local users to cause a denial of service, resulting in a deadlock and system halt, by performing specific operations on the same file, involving
mmap and write operations.Recommendations
For Sun Solaris versions 8 through 10, consider applying configuration changes to restrict access to sensitive files and minimize the risk of exploitation.
For OpenSolaris versions prior to snv 103, update to a version after snv 103 to resolve the issue.
As a temporary workaround, consider restricting the use of
mmap and write operations on the same file to minimize the risk of deadlock and system halt.Fix
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensolaris
Sun Solaris