Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-2644 | First vendor Publication | 2009-07-29 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:N/I:N/A:C) | |||
---|---|---|---|
Cvss Base Score | 4.9 | Attack Range | Local |
Cvss Impact Score | 6.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allows local users to cause a denial of service (panic) via vectors related to "pathnames for invalid fds." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2644 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-362 | Race Condition |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:6168 | |||
Oval ID: | oval:org.mitre.oval:def:6168 | ||
Title: | Race Condition Security Vulnerability in Solaris Auditing Related to Extended File Attributes May Allow Local Unprivileged Users to Panic the System | ||
Description: | Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allows local users to cause a denial of service (panic) via vectors related to "pathnames for invalid fds." | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2009-2644 | Version: | 1 |
Platform(s): | Sun Solaris 9 Sun Solaris 10 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
56607 | Solaris Auditing Subsystem Extended File Attributes Race Condition Local DoS Solaris contains a flaw that may allow a malicious local user to perform a denial of service. The issue is triggered by unspecified use of "pathnames for invalid fds." It is possible that the flaw may allow denial of service via kernel panic resulting in a loss of availability. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-03-18 | Name : The remote host is missing Sun Security Patch number 122300-61 File : solaris9_122300.nasl - Type : ACT_GATHER_INFO |
2007-03-18 | Name : The remote host is missing Sun Security Patch number 122301-61 File : solaris9_x86_122301.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:10:47 |
|
2024-11-28 12:19:29 |
|
2021-05-04 12:09:52 |
|
2021-04-22 01:10:13 |
|
2020-05-23 00:24:05 |
|
2017-09-19 09:23:19 |
|
2016-04-26 19:00:24 |
|
2014-02-17 10:50:58 |
|
2013-05-10 23:54:41 |
|