Overview
Solaris 8 systems that accept IPv6 traffic may be subject to denial of service attacks from arbitrary remote attackers.
Description
Sun Microsystems has reported that systems running Solaris 8 may encounter a system panic in response to IPv6 packets with certain characteristics. Sun Alert Notification 55301 does not provide any information about the characteristics of the offending packet, so it may be possible to exploit this vulnerability with valid IPv6 traffic. Sun Microsystems reports that this vulnerability does not affect systems running Solaris 2.6, Solaris 7, and Solaris 9. For additional information, please read the Sun Alert Notification 55301, available at: |
Impact
This vulnerability allows arbitrary remote attackers to conduct denial of service attacks on affected systems. |
Solution
Apply a patch
|
Disable IPv6
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This document was written by Jeffrey P. Lanza and is based on information provided by Sun Microsystems.
Other Information
CVE IDs: | None |
Severity Metric: | 25.20 |
Date Public: | 2003-07-21 |
Date First Published: | 2003-07-23 |
Date Last Updated: | 2003-07-23 17:06 UTC |
Document Revision: | 8 |