Vulnerability Description
Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable researcher that this is an issue in the glob implementation in libc that allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Sunos | 5.8 |
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10598
- http://secunia.com/advisories/42984
- http://secunia.com/advisories/43433
- http://secunia.com/advisories/55212
- http://securityreason.com/achievement_securityalert/89
- http://securityreason.com/achievement_securityalert/97
- http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.htmlVendor Advisory
- http://www.securitytracker.com/id?1024975
- http://www.vupen.com/english/advisories/2011/0151
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64798
- https://support.avaya.com/css/P8/documents/100127892
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10598
- http://secunia.com/advisories/42984
- http://secunia.com/advisories/43433
- http://secunia.com/advisories/55212
FAQ
What is CVE-2010-2632?
CVE-2010-2632 is a vulnerability with a CVSS score of 7.8 (HIGH). Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability. NOTE: the previous information was obtained from the January 2011...
How severe is CVE-2010-2632?
CVE-2010-2632 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2632?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Sunos.