Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96...
Vulnerability Description
Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a denial of service (panic) via a call to the sendfile system call, as reachable through the sendfilev library.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-3666
Credits & Attribution
No credits recorded in the NVD database.
References
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5128
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-239186-1
- http://www.vupen.com/english/advisories/2008/2337
- http://osvdb.org/47375
- http://secunia.com/advisories/31426
- http://www.securitytracker.com/id?1020666
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44396
- http://www.securityfocus.com/bid/30654
More from sun
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.