Security Vulnerability Relating to the acl(2) System Call May Allow Denial of Service (DoS) to the System |
|
| Category : | Security |
| Release Phase : | Resolved |
| Product : | Solaris 10 Operating System
|
| Bug Id : | 6492109
|
| Date of Resolved Release : | 07-MAY-2007
|
Impact
A security vulnerability in Solaris 10 related to the acl(2) system call may allow a local unprivileged user to cause the system to panic, resulting in a denial of service (DoS) to the system.
Sun acknowledges with thanks, iDefense (http://www.idefense.com), for bringing this issue to our attention.
This issue is also described in the following document:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=524
Contributing Factors
This issue can occur in the following releases:
SPARC Platform
x86 Platform
Note: Solaris 8 and 9 are not affected by this issue.
Symptoms
Should the described issue occur, the system may panic with a stack trace similar to the following:
unix:panicsys+0x48
unix:vpanic_common+0x78
unix:panic+0x1c
genunix:vmem_xalloc+0x8b0
genunix:vmem_alloc+0x1d4
Workaround
There is no workaround for this issue. Please see the Resolution section below.
Resolution
This issue is addressed in the following releases:
SPARC Platform
x86 Platform
AttachmentsThis solution has no attachment