Sun Solaris Kerberos Incremental Propagation Remote Denial Of Service Vulnerability
BID:34139
Info
Sun Solaris Kerberos Incremental Propagation Remote Denial Of Service Vulnerability
| Bugtraq ID: | 34139 |
| Class: | Design Error |
| CVE: |
CVE-2009-0923 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2009 12:00AM |
| Updated: | Apr 16 2009 02:46PM |
| Credit: | Sun |
| Vulnerable: |
Sun Solaris 10_x86 Sun Solaris 10 Sun OpenSolaris build snv_96 Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_91 Sun OpenSolaris build snv_90 Sun OpenSolaris build snv_89 Sun OpenSolaris build snv_88 Sun OpenSolaris build snv_87 Sun OpenSolaris build snv_85 Sun OpenSolaris build snv_80 Sun OpenSolaris build snv_68 Sun OpenSolaris build snv_67 Sun OpenSolaris build snv_64 Sun OpenSolaris build snv_59 Sun OpenSolaris build snv_57 Sun OpenSolaris build snv_50 Sun OpenSolaris build snv_39 Sun OpenSolaris build snv_36 Sun OpenSolaris build snv_22 Sun OpenSolaris build snv_19 Sun OpenSolaris build snv_13 Sun OpenSolaris build snv_110 Sun OpenSolaris build snv_109 Sun OpenSolaris build snv_108 Sun OpenSolaris build snv_107 Sun OpenSolaris build snv_106 Sun OpenSolaris build snv_105 Sun OpenSolaris build snv_104 Sun OpenSolaris build snv_103 Sun OpenSolaris build snv_102 Sun OpenSolaris build snv_100 Sun OpenSolaris build snv_02 Sun OpenSolaris build snv_01 Sun OpenSolaris 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service - CCSS7 0 Avaya CMS Server 15.0 |
| Not Vulnerable: |
Sun OpenSolaris build snv_111 |
Discussion
Sun Solaris Kerberos Incremental Propagation Remote Denial Of Service Vulnerability
Sun Solaris Kerberos is prone to a remote denial-of-service vulnerability.
An attacker may exploit this issue to prevent incremental propagation of messages from master to slave Key Distribution Center (KDC) servers, resulting in denial-of-service conditions.
The issue affects Solaris 10 and OpenSolaris based on builds snv_01 through snv_110.
Sun Solaris Kerberos is prone to a remote denial-of-service vulnerability.
An attacker may exploit this issue to prevent incremental propagation of messages from master to slave Key Distribution Center (KDC) servers, resulting in denial-of-service conditions.
The issue affects Solaris 10 and OpenSolaris based on builds snv_01 through snv_110.
Exploit / POC
Sun Solaris Kerberos Incremental Propagation Remote Denial Of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Sun Solaris Kerberos Incremental Propagation Remote Denial Of Service Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
Sun Solaris Kerberos Incremental Propagation Remote Denial Of Service Vulnerability
References:
References:
- Sun Solaris Homepage (Sun Microsystems)
- ASA-2009-102 A Security Vulnerability in Kerberos Incremental Propagation (Avaya)
- Nortel Response to Sun Alert 249926 - Solaris Kerberos Potential DoS Vulnerabili (Nortel Networks)
- Solution 249926: A Security Vulnerability in Kerberos Incremental Propagation Ma (Sun)