Executive Summary

Summary
Title Sun Alert 103021 Solaris 10 Systems May Panic or Hang When Running Certain DTrace D Programs
Informations
Name SUN-103021 First vendor Publication 2007-08-02
Vendor Sun Last vendor Modification 2007-08-02
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:S/C:N/I:N/A:P)
Cvss Base Score 1.5 Attack Range Local
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 2.7 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

Product: Solaris 10 Operating System

A security vulnerability in the DTrace (see dtrace(1M)) dynamic tracing framework may allow a local user who has privileges to run certain DTrace programs to cause the system to panic or become unresponsive. This is a type of Denial of Service (DoS). The minimum privilege required is the PRIV_DTRACE_USER privilege (see privileges(5)).

Avoidance: Patch, Workaround
State: Resolved
First released: 30-Jul-2007

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_103021_solaris_10

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:9039
 
Oval ID: oval:org.mitre.oval:def:9039
Title: Solaris 10 Systems May Panic or Hang When Running Certain DTrace D Programs
Description: Unspecified vulnerability in the dynamic tracing framework (DTrace) on Sun Solaris 10 before 20070730 allows local users with PRIV_DTRACE_USER privileges to cause a denial of service (panic or hang) via unspecified use of certain DTrace programs.
Family: unix Class: vulnerability
Reference(s): CVE-2007-4126
Version: 1
Platform(s): Sun Solaris 10
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 2

Open Source Vulnerability Database (OSVDB)

Id Description
36613 Solaris DTrace PRIV_DTRACE_USER Local DoS

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2016-04-26 13:53:29
  • Multiple Updates