Security Vulnerability May Allow Firewall Compromise or Creation of Denial of Service (DoS) Condition



Category :Security
Release Phase :Resolved
Bug Id :6240205  
Product :Solaris 9 Operating System
Solaris 10 Operating System
Solaris 8 Operating System  
Date of Resolved Release :08-Feb-2008 

Security Vulnerability May Allow Firewall Compromise or Creation of Denial of Service (DoS) Condition


1. Impact

A security vulnerability in Solaris Internet Protocol (IP - see ip(7P)) implementation may allow a remote privileged user to send certain packets bypassing the security policies set by a firewall or to cause the system to panic, creating a Denial of Service (DoS) condition.

Sun acknowledges, with thanks, Mark Dowd from IBM Internet Security Systems X-Force (http://xforce.iss.net) for bringing this issue to our attention.

2. Contributing Factors

This issue can occur in the following releases:

SPARC Platform

x86 Platform

3. Symptoms

There are no predictable symptoms that would indicate the policies of a firewall have been circumvented. If the system panics due to this issue, the following stack trace may be seen:

    icmp_pkt_v6+0xxxxx
    icmp_param_problem_v6+0xxxxx
    ip_fanout_sec_proto+0xxxxx
    ip_rput_local+0xxxxx
    ip_rput+0xxxxx
    putnext+0xxxxx

4. Workaround

To work around the described issues:

As "root," set the ndd(1M) variable "ip_reass_queue_bytes" to 0 by using the following command:

    # ndd -set /dev/ip ip_reass_queue_bytes 0

This workaround will stop the system from re-assembling IP fragments. Networks which send/receive fragmented IP packets to/from the system will become unreachable.

Note: This workaround is not persistent across reboot.

5. Resolution

This issue is addressed in the following releases:

SPARC Platform

x86 Platform

For more information on Security Sun Alerts, see Sun Infodoc 91209.




Attachments
This solution has no attachment

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 200183
Article Type : Sun Alert
Last reviewed : 2008-02-08
Audience : PUBLIC
Keywords :
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article