Vulnerabilities > CVE-2009-2912 - Local Denial Of Service vulnerability in SUN Opensolaris and Solaris

047910
CVSS 4.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
local
low complexity
sun
nessus

Summary

The (1) sendfile and (2) sendfilev functions in Sun Solaris 8 through 10, and OpenSolaris before snv_110, allow local users to cause a denial of service (panic) via vectors related to vnode function calls.

Vulnerable Configurations

Part Description Count
OS
Sun
214

Nessus

  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_122300.NASL
    descriptionSunOS 5.9: Kernel Patch. Date this patch was last updated by Sun : Nov/03/11
    last seen2020-06-01
    modified2020-06-02
    plugin id24858
    published2007-03-18
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/24858
    titleSolaris 9 (sparc) : 122300-61
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS8_X86_127722.NASL
    descriptionSunOS 5.8_x86: kernel patch. Date this patch was last updated by Sun : Apr/11/11
    last seen2016-09-26
    modified2012-06-14
    plugin id40612
    published2009-08-18
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=40612
    titleSolaris 8 (x86) : 127722-05
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS8_127721.NASL
    descriptionSunOS 5.8: kernel patch. Date this patch was last updated by Sun : Apr/11/11
    last seen2016-09-26
    modified2012-06-14
    plugin id40611
    published2009-08-18
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=40611
    titleSolaris 8 (sparc) : 127721-06
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_X86_122301.NASL
    descriptionSunOS 5.9_x86: Kernel Patch. Date this patch was last updated by Sun : Nov/03/11
    last seen2020-06-01
    modified2020-06-02
    plugin id24861
    published2007-03-18
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/24861
    titleSolaris 9 (x86) : 122301-61

Oval

accepted2009-09-28T04:00:07.402-04:00
classvulnerability
contributors
namePai Peng
organizationHewlett-Packard
definition_extensions
  • commentSolaris 8 (SPARC) is installed
    ovaloval:org.mitre.oval:def:1539
  • commentSolaris 9 (SPARC) is installed
    ovaloval:org.mitre.oval:def:1457
  • commentSolaris 10 (SPARC) is installed
    ovaloval:org.mitre.oval:def:1440
  • commentSolaris 8 (x86) is installed
    ovaloval:org.mitre.oval:def:2059
  • commentSolaris 9 (x86) is installed
    ovaloval:org.mitre.oval:def:1683
  • commentSolaris 10 (x86) is installed
    ovaloval:org.mitre.oval:def:1926
descriptionThe (1) sendfile and (2) sendfilev functions in Sun Solaris 8 through 10, and OpenSolaris before snv_110, allow local users to cause a denial of service (panic) via vectors related to vnode function calls.
familyunix
idoval:org.mitre.oval:def:5692
statusaccepted
submitted2009-08-21T11:07:35.000-04:00
titleSecurity Vulnerability in the Solaris sendfile(3EXT) and sendfilev(3EXT) Extended Library Functions may Result in a Denial of Service (DoS) Condition due to a System Panic
version37