Vulnerabilities > CVE-2008-5689 - Resource Management Errors vulnerability in SUN Opensolaris and Solaris
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCGTUNPARAM IOCTL request, which triggers a NULL pointer dereference. Complete system compromise only affects x86 platforms (http://www.trapkit.de/advisories/TKADV2008-015.txt)
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Exploit-Db
description | Linux Kernel Solaris < 5.10 138888-01 - Local Root Exploit. CVE-2008-568. Local exploit for solaris platform |
file | exploits/solaris/local/15962.c |
id | EDB-ID:15962 |
last seen | 2016-02-01 |
modified | 2011-01-10 |
platform | solaris |
port | |
published | 2011-01-10 |
reporter | peri.carding |
source | https://www.exploit-db.com/download/15962/ |
title | Linux Kernel Solaris < 5.10 138888-01 - Local Root Exploit |
type | local |
Oval
accepted | 2009-02-16T04:00:23.987-05:00 | ||||||||
class | vulnerability | ||||||||
contributors |
| ||||||||
definition_extensions |
| ||||||||
description | tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCGTUNPARAM IOCTL request, which triggers a NULL pointer dereference. | ||||||||
family | unix | ||||||||
id | oval:org.mitre.oval:def:5949 | ||||||||
status | accepted | ||||||||
submitted | 2009-01-05T16:39:26.000-05:00 | ||||||||
title | Security Vulnerability in Solaris IP Tunnel Parameter Processing May Lead to a System Panic or Possible Execution of Arbitrary Code by Unprivileged Users | ||||||||
version | 35 |
References
- http://secunia.com/advisories/33160
- http://securityreason.com/securityalert/4801
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-242266-1
- http://www.exploit-db.com/exploits/15962
- http://www.securityfocus.com/archive/1/499352/100/0/threaded
- http://www.securityfocus.com/bid/32904
- http://www.securitytracker.com/id?1021464
- http://www.trapkit.de/advisories/TKADV2008-015.txt
- http://www.vupen.com/english/advisories/2008/3454
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47449
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5949