Vulnerabilities > CVE-2008-4160 - Resource Management Errors vulnerability in SUN Opensolaris and Solaris
Attack vector
LOCAL Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
COMPLETE Summary
Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via unknown vectors related to the Solaris Access Control List (ACL) implementation.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family Solaris Local Security Checks NASL id SOLARIS9_122300.NASL description SunOS 5.9: Kernel Patch. Date this patch was last updated by Sun : Nov/03/11 last seen 2020-06-01 modified 2020-06-02 plugin id 24858 published 2007-03-18 reporter This script is Copyright (C) 2007-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/24858 title Solaris 9 (sparc) : 122300-61 NASL family Solaris Local Security Checks NASL id SOLARIS10_X86_139484.NASL description SunOS 5.10_x86: ufs patch. Date this patch was last updated by Sun : Mar/12/09 last seen 2018-09-01 modified 2018-08-13 plugin id 35214 published 2008-12-17 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=35214 title Solaris 10 (x86) : 139484-05 NASL family Solaris Local Security Checks NASL id SOLARIS8_X86_117351.NASL description SunOS 5.8_x86: kernel patch. Date this patch was last updated by Sun : Mar/09/09 last seen 2020-06-01 modified 2020-06-02 plugin id 20947 published 2006-02-19 reporter This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/20947 title Solaris 8 (x86) : 117351-61 NASL family Solaris Local Security Checks NASL id SOLARIS8_117350.NASL description SunOS 5.8: kernel patch. Date this patch was last updated by Sun : Apr/21/09 last seen 2020-06-01 modified 2020-06-02 plugin id 20945 published 2006-02-19 reporter This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/20945 title Solaris 8 (sparc) : 117350-62 NASL family Solaris Local Security Checks NASL id SOLARIS9_X86_122301.NASL description SunOS 5.9_x86: Kernel Patch. Date this patch was last updated by Sun : Nov/03/11 last seen 2020-06-01 modified 2020-06-02 plugin id 24861 published 2007-03-18 reporter This script is Copyright (C) 2007-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/24861 title Solaris 9 (x86) : 122301-61 NASL family Solaris Local Security Checks NASL id SOLARIS10_139483.NASL description SunOS 5.10: ufs patch. Date this patch was last updated by Sun : Mar/12/09 last seen 2018-09-01 modified 2018-08-13 plugin id 35203 published 2008-12-17 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=35203 title Solaris 10 (sparc) : 139483-05
Oval
accepted | 2009-09-28T04:00:06.168-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||
description | Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via unknown vectors related to the Solaris Access Control List (ACL) implementation. | ||||||||||||||||||||||||
family | unix | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:5639 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2009-08-19T11:48:53.000-04:00 | ||||||||||||||||||||||||
title | Security Vulnerability in the ACL (acl(2)) Implementation for UFS File Systems May Allow a Local User to Panic the System | ||||||||||||||||||||||||
version | 36 |
References
- http://secunia.com/advisories/31919
- http://secunia.com/advisories/32125
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-242267-1
- http://support.avaya.com/elmodocs2/security/ASA-2008-383.htm
- http://www.securityfocus.com/bid/31250
- http://www.securitytracker.com/id?1020899
- http://www.vupen.com/english/advisories/2008/2626
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45236
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5639