English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Sun Solaris Sockets Direct Protocol Driver Denial of Service


Secunia ID

SA37249

CVE-ID

CVE-2009-3899

Release Date

04 Nov 2009

Last Change

10 Nov 2009

Criticality

Moderately Critical

Solution Status

Vendor Patch

Where

From remote

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.

Description

A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error in the Sockets Direct Protocol (SDP) driver (sdp(7D)) and can be exploited to exhaust all available kernel memory.

NOTE: Applications bundled with Solaris are reportedly not affected.

The vulnerability is reported in Solaris 10 and OpenSolaris on both the SPARC and x86 platforms.

Solution

Apply patches.

-- SPARC Platform --

Solaris 10:
Apply patch 141444-09 or later.

OpenSolaris:
Fixed in builds snv_95 and later.

-- x86 Platform --

Solaris 10:
Apply patch 141445-09 or later.

OpenSolaris:
Fixed in builds snv_95 and later.

Original Advisory

http://sunsolve.sun.com/search/document.do?assetkey=1-66-264730-1