A Security Vulnerability With the Special File System (SPECFS) strfreectty() Function May Allow a Local Unprivileged User to Panic a System



Category :Security
Release Phase :Resolved
Product :Solaris 9 Operating System
Solaris 10 Operating System
Solaris 8 Operating System  
Bug Id :6322179  
Date of Resolved Release :31-AUG-2007 


Impact

A security vulnerability in the Special File System (SPECFS) strfreectty() function may allow an unprivileged local user to panic the system, creating a Denial of Service (DoS).


Contributing Factors

This issue can occur in the following releases:

SPARC Platform

x86 Platform


Symptoms

The panic stack backtrace will show strfreectty() erroneously passing a NULL pointer to pgsignal().


Workaround

There is no workaround for this issue. Please see the Resolution section below.


Resolution

This issue is addressed in the following releases:

SPARC Platform

  • Solaris 8 with patches 109025-07 or later and 117350-49 or later
  • Solaris 9 with patch 122300-11 or later
  • Solaris 10 with patch 118822-24 or later

x86 Platform

  • Solaris 8 with patches 109026-08 or later and 117351-49 or later
  • Solaris 9 with patch 122301-11 or later
  • Solaris 10 with patch 118844-24 or later





Attachments
This solution has no attachment

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 201340
Article Type : Sun Alert
Last reviewed : 2007-08-31
Audience : PUBLIC
Keywords :
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article