PT-2018-1116 · Oracle · Solaris

Published

2018-01-16

·

Updated

2018-01-26

·

CVE-2018-2710

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Oracle Sun Systems Products Suite (subcomponent: Kernel) version 10
Description The issue is related to a vulnerability in the Kernel component of the Solaris operating system, which can be exploited by an unauthenticated attacker with network access via ICMP. This vulnerability can result in the ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. The exploitation of this vulnerability is considered easily exploitable.
Recommendations For version 10, apply the necessary security patches to fix the vulnerability in the Kernel component. As a temporary workaround, consider restricting access to ICMP protocol to minimize the risk of exploitation.

Fix

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00533
CVE-2018-2710

Affected Products

Solaris