Vulnerability Description
The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via a crafted IPv6 packet, related to an "insufficient validation security vulnerability," as demonstrated by SunOSipv6.c.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Opensolaris | <= snv_107 |
| Sun | Solaris | 10 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2009-January/067709.html
- http://secunia.com/advisories/33605Vendor Advisory
- http://securitytracker.com/id?1021635
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-251006-1Vendor Advisory
- http://www.securityfocus.com/bid/33435
- http://www.vupen.com/english/advisories/2009/0232Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48208
- https://www.exploit-db.com/exploits/7865
- http://lists.grok.org.uk/pipermail/full-disclosure/2009-January/067709.html
- http://secunia.com/advisories/33605Vendor Advisory
- http://securitytracker.com/id?1021635
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-251006-1Vendor Advisory
- http://www.securityfocus.com/bid/33435
- http://www.vupen.com/english/advisories/2009/0232Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48208
FAQ
What is CVE-2009-0304?
CVE-2009-0304 is a vulnerability with a CVSS score of 7.8 (HIGH). The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via a crafted IPv6 packet, related to an "insufficient...
How severe is CVE-2009-0304?
CVE-2009-0304 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0304?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Opensolaris, Sun Solaris.