Oracle Solaris Multiple Vulnerabilities
Last Update Date:
21 Jul 2011 10:21
Release Date:
21 Jul 2011
6508
Views
RISK: High Risk
TYPE: Operating Systems - Sun Solaris
Multiple vulnerabilities have been reported in Oracle Solaris, which can be exploited by malicious and local users to cause a DoS (Denial of Service), gain escalated privileges or potentially compromise a vulnerable system.
- An unspecified error in fingerd can be exploited to cause the system to hang or crash via specially crafted requests.
- An unspecified error in the SSH component can be exploited to potentially compromise a vulnerable system.
- An unspecified error in the Installer, rksh and Trusted Extensions component can be exploited to gain escalated privileges.
- An unspecified error in the TCP/IP implementation can be exploited by authenticated users to crash the system.
- An unspecified error in the SSH and KSSL component can be exploited to cause the service to stop responding or crash.
- An unspecified error in the Kernel/SCTP, Kernel/sockfs, UFS, Zones and Driver/USB component can be exploited to cause a local DoS.
- An unspecified error in the LiveUpgrade component can be exploited to manipulate certain data or cause a local DoS.
Impact
- Denial of Service
- Elevation of Privilege
- Remote Code Execution
System / Technologies affected
- Oracle Solaris versions 8, 9, 10, and 11 Express
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Vulnerability Identifier
- CVE-2011-2245
- CVE-2011-2249
- CVE-2011-2258
- CVE-2011-2259
- CVE-2011-2285
- CVE-2011-2287
- CVE-2011-2289
- CVE-2011-2290
- CVE-2011-2291
- CVE-2011-2293
- CVE-2011-2294
- CVE-2011-2295
- CVE-2011-2296
- CVE-2011-2298
Source
Related Link
Share with