Security Vulnerabilities In Solaris 10 SCTP Socket Option Processing



Category :Security
Release Phase :Resolved
Product :Solaris 10 Operating System  
Bug Id :6248555, 6250374  
Date of Resolved Release :13-OCT-2005 


Impact

Multiple security vulnerabilities in Solaris 10 SCTP Socket Option Processing (see sctp(7P)) may allow an unprivileged local user to panic the system, resulting in a Denial of Service (DoS).


Contributing Factors

These issues can occur in the following releases:

SPARC Platform

x86 Platform

Note: Solaris 7 will not be evaluated regarding the potential impact of the issue described in this Sun Alert. Solaris 8 and 9 are not impacted by this issue.


Symptoms

The system may panic with a stack trace similar to the following:

    ...
    vpanic()
    sosctp_setsockopt()
    setsockopt()
    ...

Workaround

There is no workaround. Please see the Resolution section below.


Resolution

These issues are addressed in the following releases:

SPARC Platform

x86 Platform






Attachments
This solution has no attachment

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 200480
Article Type : Sun Alert
Last reviewed : 2005-10-13
Audience : PUBLIC
Keywords :
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article