PT-2009-5215 · Sun · Opensolaris+1
CVE-2009-2857
·
Publicado
2009-08-19
·
Atualizado
2025-01-21
CVSS v2.0
4.9
Média
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 8 through 10
OpenSolaris versions prior to snv 103
Description
The issue arises from improper handling of interaction between the filesystem and virtual-memory implementations. This allows local users to cause a denial of service, resulting in a deadlock and system halt, by performing specific operations on the same file, involving
mmap and write operations.Recommendations
For Sun Solaris versions 8 through 10, consider applying configuration changes to restrict access to sensitive files and minimize the risk of exploitation.
For OpenSolaris versions prior to snv 103, update to a version after snv 103 to resolve the issue.
As a temporary workaround, consider restricting the use of
mmap and write operations on the same file to minimize the risk of deadlock and system halt.Correção
Improper Locking
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Opensolaris
Sun Solaris