Sun Solaris 'rpc.metad' Remote Denial of Service Vulnerability
BID:28261
Info
Sun Solaris 'rpc.metad' Remote Denial of Service Vulnerability
| Bugtraq ID: | 28261 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-1480 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 15 2008 12:00AM |
| Updated: | Jan 22 2009 04:32PM |
| Credit: | Kingcope discovered this issue. |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 9 Sun Solaris 10_x86 Sun Solaris 10_sparc Sun Solaris 10.0_x86 Sun Solaris 10.0 Sun Solaris 10 Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_91 Sun OpenSolaris build snv_90 Sun OpenSolaris build snv_89 Sun OpenSolaris build snv_88 Sun OpenSolaris build snv_87 Sun OpenSolaris build snv_85 Sun OpenSolaris build snv_84 Sun OpenSolaris build snv_83 Sun OpenSolaris build snv_82 Sun OpenSolaris build snv_80 Sun OpenSolaris build snv_77 Sun OpenSolaris build snv_76 Sun OpenSolaris build snv_68 Sun OpenSolaris build snv_67 Sun OpenSolaris build snv_64 Sun OpenSolaris build snv_59 Sun OpenSolaris build snv_57 Sun OpenSolaris build snv_50 Sun OpenSolaris build snv_39 Sun OpenSolaris build snv_36 Sun OpenSolaris build snv_22 Sun OpenSolaris build snv_19 Sun OpenSolaris build snv_13 Sun OpenSolaris build snv_02 Sun OpenSolaris build snv_01 Avaya Interactive Response 3.0 Avaya Interactive Response 2.0 Avaya CMS Server 13.0 Avaya CMS Server 14.1 Avaya CMS Server 14.0 Avaya CMS Server 13.1 |
| Not Vulnerable: |
Sun OpenSolaris build snv_96 |
Discussion
Sun Solaris 'rpc.metad' Remote Denial of Service Vulnerability
Sun Solaris 'rpc.metad' is prone to a denial-of-service vulnerability because it fails to handle specially crafted network data.
A remote attacker can exploit this issue to cause the affected application to crash, resulting in a denial-of-service condition.
The following are vulnerable to this issue:
Solstice Disk Suite 4.2.1
Solaris 9 Operating System
Solaris 10 Operating System
OpenSolaris
Sun Solaris 'rpc.metad' is prone to a denial-of-service vulnerability because it fails to handle specially crafted network data.
A remote attacker can exploit this issue to cause the affected application to crash, resulting in a denial-of-service condition.
The following are vulnerable to this issue:
Solstice Disk Suite 4.2.1
Solaris 9 Operating System
Solaris 10 Operating System
OpenSolaris
Exploit / POC
Sun Solaris 'rpc.metad' Remote Denial of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Sun Solaris 'rpc.metad' Remote Denial of Service Vulnerability
Solution:
Vendor fixes are available; please see the references for more information.
Sun Solaris 10.0
Sun Solaris 10_sparc
Sun Solaris 10.0_x86
Sun Solaris 10_x86
Sun Solaris 10
Sun Solaris 9
Sun Solaris 9_x86
Solution:
Vendor fixes are available; please see the references for more information.
Sun Solaris 10.0
-
Sun 138632-03
for SPARC
http://sunsolve.sun.com/pdownload.do?target=138632-03&method=h -
Sun 138882-02
for x86
http://sunsolve.sun.com/pdownload.do?target=138882-02&method=h
Sun Solaris 10_sparc
-
Sun 138632-03
for SPARC
http://sunsolve.sun.com/pdownload.do?target=138632-03&method=h
Sun Solaris 10.0_x86
-
Sun 138882-02
for x86
http://sunsolve.sun.com/pdownload.do?target=138882-02&method=h
Sun Solaris 10_x86
-
Sun 138882-02
for x86
http://sunsolve.sun.com/pdownload.do?target=138882-02&method=h
Sun Solaris 10
-
Sun 138632-03
for SPARC
http://sunsolve.sun.com/pdownload.do?target=138632-03&method=h -
Sun 138882-02
for x86
http://sunsolve.sun.com/pdownload.do?target=138882-02&method=h
Sun Solaris 9
-
Sun 116669-34
for SPARC
http://sunsolve.sun.com/pdownload.do?target=116669-34&method=h -
Sun 138574-01
for x86
http://sunsolve.sun.com/pdownload.do?target=138574-01&method=h
Sun Solaris 9_x86
-
Sun 116669-34
for SPARC
http://sunsolve.sun.com/pdownload.do?target=116669-34&method=h -
Sun 138574-01
for x86
http://sunsolve.sun.com/pdownload.do?target=138574-01&method=h
References
Sun Solaris 'rpc.metad' Remote Denial of Service Vulnerability
References:
References: