PT-2009-6153 · Sun · Opensolaris

Published

2009-11-13

·

Updated

2009-11-16

·

CVE-2009-3937

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Sun OpenSolaris versions snv 106 through snv 126
Description The issue is related to a memory leak in Solaris TCP sockets, which can be exploited by local users to cause a denial of service. This is achieved through unspecified vectors involving tcp sendmsg processing of "ancillary data."
Recommendations For Sun OpenSolaris versions snv 106 through snv 126, consider restricting access to tcp sendmsg processing to minimize the risk of exploitation until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3937

Affected Products

Opensolaris