Vulnerabilities > CVE-2009-0870 - Resource Management Errors vulnerability in SUN Opensolaris and Solaris
Attack vector
LOCAL Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
COMPLETE Summary
The NFSv4 Server module in the kernel in Sun Solaris 10, and OpenSolaris before snv_111, allow local users to cause a denial of service (infinite loop and system hang) by accessing an hsfs filesystem that is shared through NFSv4, related to the rfs4_op_readdir function.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family Solaris Local Security Checks NASL id SOLARIS10_139462-02.NASL description SunOS 5.10: nfssrv patch. Date this patch was last updated by Sun : Mar/05/09 last seen 2020-06-01 modified 2020-06-02 plugin id 107514 published 2018-03-12 reporter This script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/107514 title Solaris 10 (sparc) : 139462-02 code #%NASL_MIN_LEVEL 80502 # # (C) Tenable Network Security, Inc. # # The descriptive text in this plugin was # extracted from the Oracle SunOS Patch Updates. # include("compat.inc"); if (description) { script_id(107514); script_version("1.6"); script_cvs_date("Date: 2019/10/25 13:36:25"); script_cve_id("CVE-2009-0870", "CVE-2009-0872", "CVE-2009-0873"); script_name(english:"Solaris 10 (sparc) : 139462-02"); script_summary(english:"Check for patch 139462-02"); script_set_attribute( attribute:"synopsis", value:"The remote host is missing Sun Security Patch number 139462-02" ); script_set_attribute( attribute:"description", value: "SunOS 5.10: nfssrv patch. Date this patch was last updated by Sun : Mar/05/09" ); script_set_attribute( attribute:"see_also", value:"https://download.oracle.com/sunalerts/1020173.1.html" ); script_set_attribute(attribute:"solution", value:"Install patch 139462-02"); script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P"); script_cwe_id(264, 399); script_set_attribute(attribute:"plugin_type", value:"local"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:oracle:solaris:10:139462"); script_set_attribute(attribute:"cpe", value:"cpe:/o:oracle:solaris:10"); script_set_attribute(attribute:"patch_publication_date", value:"2009/03/05"); script_set_attribute(attribute:"plugin_publication_date", value:"2018/03/12"); script_set_attribute(attribute:"generated_plugin", value:"current"); script_end_attributes(); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof."); script_family(english:"Solaris Local Security Checks"); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/local_checks_enabled", "Host/Solaris/showrev"); exit(0); } include("audit.inc"); include("global_settings.inc"); include("misc_func.inc"); include("solaris.inc"); showrev = get_kb_item("Host/Solaris/showrev"); if (empty_or_null(showrev)) audit(AUDIT_OS_NOT, "Solaris"); os_ver = pregmatch(pattern:"Release: (\d+.(\d+))", string:showrev); if (empty_or_null(os_ver)) audit(AUDIT_UNKNOWN_APP_VER, "Solaris"); full_ver = os_ver[1]; os_level = os_ver[2]; if (full_ver != "5.10") audit(AUDIT_OS_NOT, "Solaris 10", "Solaris " + os_level); package_arch = pregmatch(pattern:"Application architecture: (\w+)", string:showrev); if (empty_or_null(package_arch)) audit(AUDIT_UNKNOWN_ARCH); package_arch = package_arch[1]; if (package_arch != "sparc") audit(AUDIT_ARCH_NOT, "sparc", package_arch); if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED); if (solaris_check_patch(release:"5.10", arch:"sparc", patch:"139462-02", obsoleted_by:"141444-09 139991-02 141733-02 141414-09 ", package:"SUNWnfsskr", version:"11.10.0,REV=2005.01.21.15.53") < 0) flag++; if (flag) { security_report_v4( port : 0, severity : SECURITY_WARNING, extra : solaris_get_report() ); } else { patch_fix = solaris_patch_fix_get(); if (!empty_or_null(patch_fix)) audit(AUDIT_PATCH_INSTALLED, patch_fix, "Solaris 10"); tested = solaris_pkg_tests_get(); if (!empty_or_null(tested)) audit(AUDIT_PACKAGE_NOT_AFFECTED, tested); audit(AUDIT_PACKAGE_NOT_INSTALLED, "SUNWnfsskr"); }
NASL family Solaris Local Security Checks NASL id SOLARIS10_X86_139463.NASL description SunOS 5.10_x86: nfssrv patch. Date this patch was last updated by Sun : Mar/05/09 last seen 2018-09-02 modified 2018-08-13 plugin id 36795 published 2009-04-23 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=36795 title Solaris 10 (x86) : 139463-02 code #%NASL_MIN_LEVEL 80502 # @DEPRECATED@ # # This script has been deprecated as the associated patch is not # currently a recommended security fix. # # Disabled on 2011/10/24. # # # (C) Tenable Network Security, Inc. # # if ( ! defined_func("bn_random") ) exit(0); include("compat.inc"); if(description) { script_id(36795); script_version("1.17"); script_name(english: "Solaris 10 (x86) : 139463-02"); script_cve_id("CVE-2009-0870", "CVE-2009-0872", "CVE-2009-0873"); script_set_attribute(attribute: "synopsis", value: "The remote host is missing Sun Security Patch number 139463-02"); script_set_attribute(attribute: "description", value: 'SunOS 5.10_x86: nfssrv patch. Date this patch was last updated by Sun : Mar/05/09'); script_set_attribute(attribute: "solution", value: "You should install this patch for your system to be up-to-date."); script_set_attribute(attribute: "see_also", value: "http://download.oracle.com/sunalerts/1020173.1.html"); script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P"); script_cwe_id(264); script_set_attribute(attribute:"plugin_publication_date", value: "2009/04/23"); script_cvs_date("Date: 2019/10/25 13:36:25"); script_end_attributes(); script_summary(english: "Check for patch 139463-02"); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2009-2019 Tenable Network Security, Inc."); family["english"] = "Solaris Local Security Checks"; script_family(english:family["english"]); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/Solaris/showrev"); exit(0); } # Deprecated. exit(0, "The associated patch is not currently a recommended security fix.");
NASL family Solaris Local Security Checks NASL id SOLARIS10_139462.NASL description SunOS 5.10: nfssrv patch. Date this patch was last updated by Sun : Mar/05/09 last seen 2018-09-02 modified 2018-08-13 plugin id 36339 published 2009-04-23 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=36339 title Solaris 10 (sparc) : 139462-02 NASL family Solaris Local Security Checks NASL id SOLARIS10_X86_139463-02.NASL description SunOS 5.10_x86: nfssrv patch. Date this patch was last updated by Sun : Mar/05/09 last seen 2020-06-01 modified 2020-06-02 plugin id 108011 published 2018-03-12 reporter This script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/108011 title Solaris 10 (x86) : 139463-02
References
- http://secunia.com/advisories/34193
- http://secunia.com/advisories/34371
- http://securitytracker.com/id?1021819
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-139462-02-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-252469-1
- http://support.avaya.com/elmodocs2/security/ASA-2009-090.htm
- http://www.securityfocus.com/bid/34031
- http://www.vupen.com/english/advisories/2009/0635
- http://www.vupen.com/english/advisories/2009/0765
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49133