Sun Solaris LDAP Client Configuration Cache Daemon Local Denial of Service Vulnerability
BID:37129
Info
Sun Solaris LDAP Client Configuration Cache Daemon Local Denial of Service Vulnerability
| Bugtraq ID: | 37129 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 25 2009 12:00AM |
| Updated: | Dec 15 2009 08:23PM |
| Credit: | Sun |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9 Update 5 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10.0_x86 Sun Solaris 10.0 Sun OpenSolaris build snv_77 Sun OpenSolaris build snv_76 Sun OpenSolaris build snv_68 Sun OpenSolaris build snv_67 Sun OpenSolaris build snv_64 Sun OpenSolaris build snv_61 Sun OpenSolaris build snv_59 Sun OpenSolaris build snv_58 Sun OpenSolaris build snv_57 Sun OpenSolaris build snv_54 Sun OpenSolaris build snv_51 Sun OpenSolaris build snv_50 Sun OpenSolaris build snv_49 Sun OpenSolaris build snv_48 Sun OpenSolaris build snv_47 Sun OpenSolaris build snv_45 Sun OpenSolaris build snv_41 Sun OpenSolaris build snv_39 Sun OpenSolaris build snv_38 Sun OpenSolaris build snv_37 Sun OpenSolaris build snv_36 Sun OpenSolaris build snv_29 Sun OpenSolaris build snv_28 Sun OpenSolaris build snv_22 Sun OpenSolaris build snv_19 Sun OpenSolaris build snv_13 Sun OpenSolaris build snv_02 Sun OpenSolaris build snv_01 Avaya CMS Server 14.1 Avaya CMS Server 14.0 |
| Not Vulnerable: |
Sun OpenSolaris build snv_78 |
Discussion
Sun Solaris LDAP Client Configuration Cache Daemon Local Denial of Service Vulnerability
Sun Solaris is prone to a local denial-of-service vulnerabilities.
An attacker can exploit this issue to cause the LDAP 'ldap_cachemgr' daemon to terminate, denying service to legitimate users. Note that on Solaris 9 and 10, the LDAP name service will stop responding; on Solaris 8, it will slow down.
This issue affects the following:
Solaris 8
Solaris 9
Solaris 10
OpenSolaris builds snv_01 through snv_77
Sun Solaris is prone to a local denial-of-service vulnerabilities.
An attacker can exploit this issue to cause the LDAP 'ldap_cachemgr' daemon to terminate, denying service to legitimate users. Note that on Solaris 9 and 10, the LDAP name service will stop responding; on Solaris 8, it will slow down.
This issue affects the following:
Solaris 8
Solaris 9
Solaris 10
OpenSolaris builds snv_01 through snv_77
Exploit / POC
Sun Solaris LDAP Client Configuration Cache Daemon Local Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Sun Solaris LDAP Client Configuration Cache Daemon Local Denial of Service Vulnerability
Solution:
The vendor has released updates. Please see the references for details.
Sun Solaris 10_x86
Sun Solaris 9_x86
Solution:
The vendor has released updates. Please see the references for details.
Sun Solaris 10_x86
Sun Solaris 9_x86
References
Sun Solaris LDAP Client Configuration Cache Daemon Local Denial of Service Vulnerability
References:
References:
- Sun Solaris Homepage (Sun Microsystems)
- ASA-2009-569 Denial of Service Vulnerabilities in ldap_cachemgr(1M) Daemon (Sun (Avaya)
- Denial of Service Vulnerabilities in ldap_cachemgr(1M) Daemon (Sun Microsystems)