Vulnerability Description
The squeue_drain function in Sun Solaris 10, possibly only when run on CMT processors, allows remote attackers to cause a denial of service ("bad trap" and system panic) by opening and closing a large number of TCP connections ("heavy TCP/IP loads"). NOTE: the original report specifies the function name as "drain_squeue," but this is likely incorrect.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Solaris | 10.0 |
References
- http://secunia.com/advisories/21453Vendor Advisory
- http://securitytracker.com/id?1016674
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102554-1
- http://www.vupen.com/english/advisories/2006/3239
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28321
- http://secunia.com/advisories/21453Vendor Advisory
- http://securitytracker.com/id?1016674
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102554-1
- http://www.vupen.com/english/advisories/2006/3239
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28321
FAQ
What is CVE-2006-4117?
CVE-2006-4117 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The squeue_drain function in Sun Solaris 10, possibly only when run on CMT processors, allows remote attackers to cause a denial of service ("bad trap" and system panic) by opening and closing a large...
How severe is CVE-2006-4117?
CVE-2006-4117 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4117?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Solaris.