Executive Summary

Summary
Title Sun Alert 258588 Security Vulnerability in the Solaris sendfile(3EXT) and sendfilev(3EXT) Extended Library Functions may Result in a Denial of Service (DoS) Condition due to a System Panic
Informations
Name SUN-258588 First vendor Publication 2009-08-18
Vendor Sun Last vendor Modification 2010-01-21
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:N/I:N/A:C)
Cvss Base Score 4.9 Attack Range Local
Cvss Impact Score 6.9 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Product: Solaris 8, Solaris 9, Solaris 10, OpenSolaris

A security vulnerability in the Solaris sendfile(3EXT) andsendfilev(3EXT) extended library functions may allow a localunprivileged user to panic the system, causing a Denial of Service(DoS).

State: Resolved
First released: 18-Aug-2009

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_258588_security_vulnerability

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:5692
 
Oval ID: oval:org.mitre.oval:def:5692
Title: Security Vulnerability in the Solaris sendfile(3EXT) and sendfilev(3EXT) Extended Library Functions may Result in a Denial of Service (DoS) Condition due to a System Panic
Description: The (1) sendfile and (2) sendfilev functions in Sun Solaris 8 through 10, and OpenSolaris before snv_110, allow local users to cause a denial of service (panic) via vectors related to vnode function calls.
Family: unix Class: vulnerability
Reference(s): CVE-2009-2912
Version: 1
Platform(s): Sun Solaris 8
Sun Solaris 9
Sun Solaris 10
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 348
Os 6

Open Source Vulnerability Database (OSVDB)

Id Description
57169 Solaris sendfile / sendfilev Extended Library Functions Unspecified DoS

Nessus® Vulnerability Scanner

Date Description
2007-03-18 Name : The remote host is missing Sun Security Patch number 122300-61
File : solaris9_122300.nasl - Type : ACT_GATHER_INFO
2007-03-18 Name : The remote host is missing Sun Security Patch number 122301-61
File : solaris9_x86_122301.nasl - Type : ACT_GATHER_INFO