Vulnerabilities > CVE-2008-4160 - Resource Management Errors vulnerability in SUN Opensolaris and Solaris

047910
CVSS 4.7 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
local
sun
CWE-399
nessus

Summary

Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via unknown vectors related to the Solaris Access Control List (ACL) implementation.

Vulnerable Configurations

Part Description Count
OS
Sun
177

Common Weakness Enumeration (CWE)

Nessus

  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_122300.NASL
    descriptionSunOS 5.9: Kernel Patch. Date this patch was last updated by Sun : Nov/03/11
    last seen2020-06-01
    modified2020-06-02
    plugin id24858
    published2007-03-18
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/24858
    titleSolaris 9 (sparc) : 122300-61
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_X86_139484.NASL
    descriptionSunOS 5.10_x86: ufs patch. Date this patch was last updated by Sun : Mar/12/09
    last seen2018-09-01
    modified2018-08-13
    plugin id35214
    published2008-12-17
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=35214
    titleSolaris 10 (x86) : 139484-05
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS8_X86_117351.NASL
    descriptionSunOS 5.8_x86: kernel patch. Date this patch was last updated by Sun : Mar/09/09
    last seen2020-06-01
    modified2020-06-02
    plugin id20947
    published2006-02-19
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/20947
    titleSolaris 8 (x86) : 117351-61
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS8_117350.NASL
    descriptionSunOS 5.8: kernel patch. Date this patch was last updated by Sun : Apr/21/09
    last seen2020-06-01
    modified2020-06-02
    plugin id20945
    published2006-02-19
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/20945
    titleSolaris 8 (sparc) : 117350-62
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_X86_122301.NASL
    descriptionSunOS 5.9_x86: Kernel Patch. Date this patch was last updated by Sun : Nov/03/11
    last seen2020-06-01
    modified2020-06-02
    plugin id24861
    published2007-03-18
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/24861
    titleSolaris 9 (x86) : 122301-61
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_139483.NASL
    descriptionSunOS 5.10: ufs patch. Date this patch was last updated by Sun : Mar/12/09
    last seen2018-09-01
    modified2018-08-13
    plugin id35203
    published2008-12-17
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=35203
    titleSolaris 10 (sparc) : 139483-05

Oval

accepted2009-09-28T04:00:06.168-04:00
classvulnerability
contributors
namePai Peng
organizationHewlett-Packard
definition_extensions
  • commentSolaris 8 (SPARC) is installed
    ovaloval:org.mitre.oval:def:1539
  • commentSolaris 9 (SPARC) is installed
    ovaloval:org.mitre.oval:def:1457
  • commentSolaris 10 (SPARC) is installed
    ovaloval:org.mitre.oval:def:1440
  • commentSolaris 8 (x86) is installed
    ovaloval:org.mitre.oval:def:2059
  • commentSolaris 9 (x86) is installed
    ovaloval:org.mitre.oval:def:1683
  • commentSolaris 10 (x86) is installed
    ovaloval:org.mitre.oval:def:1926
descriptionUnspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via unknown vectors related to the Solaris Access Control List (ACL) implementation.
familyunix
idoval:org.mitre.oval:def:5639
statusaccepted
submitted2009-08-19T11:48:53.000-04:00
titleSecurity Vulnerability in the ACL (acl(2)) Implementation for UFS File Systems May Allow a Local User to Panic the System
version36