Executive Summary

Summary
Title Sun Alert 103083 Race Condition in the Solaris Remote Procedure Calls (RPC) Module May Result in a System Panic
Informations
Name SUN-103083 First vendor Publication 2007-11-28
Vendor Sun Last vendor Modification 2007-11-28
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:A/AC:M/Au:N/C:P/I:C/A:C)
Cvss Base Score 7.6 Attack Range Adjacent network
Cvss Impact Score 9.5 Attack Complexity Medium
Cvss Expoit Score 5.5 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Product: Solaris 9 Operating System, Solaris 10 Operating System, Solaris 8 Operating System

A race condition security vulnerability in the Solaris Remote Procedure Call (RPC) Module may allow a local unprivileged user to panic the system, resulting in a Denial of Service (DoS) condition.

Avoidance: Patch
State: Resolved
First released: 28-Nov-2007

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_103083_race_condition

CAPEC : Common Attack Pattern Enumeration & Classification

Id Name
CAPEC-26 Leveraging Race Conditions
CAPEC-29 Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-362 Race Condition

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 6

Open Source Vulnerability Database (OSVDB)

Id Description
40821 Solaris Remote Procedure Call kernel Module (rpcmod) Unspecified Local Race C...

Nessus® Vulnerability Scanner

Date Description
2006-10-05 Name : The remote host is missing Sun Security Patch number 116959-21
File : solaris8_116959.nasl - Type : ACT_GATHER_INFO
2006-10-05 Name : The remote host is missing Sun Security Patch number 116960-21
File : solaris8_x86_116960.nasl - Type : ACT_GATHER_INFO