CVE-2008-1317 |
|
发布时间 :2008-03-13 10:44:00 | ||
修订时间 :2011-03-07 22:06:42 | ||||
NMCO |
[原文]Unspecified vulnerability in the Inter-Process Communication (IPC) message queue subsystem in Sun Solaris 10 allows local users to cause a denial of service (reboot) via blocked I/O message queues.
[CNNVD]Sun Solaris Inter-Process Communication (IPC) 本地拒绝服务漏洞(CNNVD-200803-212)
Sun Solaris 10的进程间通信(IPC)信息排队系统中的未明漏洞。本地用户通过封闭的I/O信息排队来引起一个拒绝服务(重新启动)。
–
CVSS (基础分值)
CVSS分值: | 4.9 | [中等(MEDIUM)] |
机密性影响: | NONE | [对系统的机密性无影响] |
完整性影响: | NONE | [不会对系统完整性产生影响] |
可用性影响: | COMPLETE | [可能导致系统完全宕机] |
攻击复杂度: | LOW | [漏洞利用没有访问限制 ] |
攻击向量: | LOCAL | [漏洞利用需要具有物理访问权限或本地帐户] |
身份认证: | NONE | [漏洞利用无需身份认证] |
–
CPE (受影响的平台与产品)
cpe:/o:sun:solaris:10::x86 | |
cpe:/o:sun:solaris:10::sparc |
–
OVAL (用于检测的技术细节)
未找到相关OVAL定义 |
–
官方数据库链接
–
其它链接及资源
http://www.securityfocus.com/bid/28214 (PATCH) BID 28214 |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-231403-1 (PATCH) SUNALERT 231403 |
http://xforce.iss.net/xforce/xfdb/41146 (UNKNOWN) XF sun-solaris-ipc-dos(41146) |
http://www.vupen.com/english/advisories/2008/0858/references (UNKNOWN) VUPEN ADV-2008-0858 |
http://secunia.com/advisories/29352 (VENDOR_ADVISORY) SECUNIA 29352 |
–
漏洞信息
Sun Solaris Inter-Process Communication (IPC) 本地拒绝服务漏洞 | |
中危 | 资料不足 |
2008-03-13 00:00:00 | 2008-09-05 00:00:00 |
本地 | |
Sun Solaris 10的进程间通信(IPC)信息排队系统中的未明漏洞。本地用户通过封闭的I/O信息排队来引起一个拒绝服务(重新启动)。 |
–
公告与补丁
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接: Sun Solaris 10 Sun 127111-10 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -127111-10-1 Sun Solaris 10_x86 Sun 127112-10 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -127112-10-1 |
–
漏洞信息
42831 |
|
Solaris 10 Inter-Process Communication (IPC) Message Queue Sub-system Local DoS | |
Local Access Required |
Denial of Service |
Loss of Availability | Patch / RCS |
Vendor Verified |
–
漏洞描述
–
时间线
2008-03-11 |
Unknow |
Unknow | 2008-03-11 |
–
解决方案
Currently, there are no known workarounds or upgrades to correct this issue. However, Sun has released patch 127112-10 to address this vulnerability. |
–
相关参考
|
–
漏洞作者
Unknown or Incomplete |