search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Sun Solaris contains a vulnerability in the tcsetattr() library function

Vulnerability Note VU#379390

Original Release Date: 2004-03-31 | Last Revised: 2004-04-05

Overview

A vulnerability in the Sun Solaris tcsetattr() library function could allow a unprivileged local user to cause the system to hang.

Description

Sun Solaris uses a tcsetattr() library function to set the parameters associated with the terminal. There is an unspecified vulnerability in the tcsetattr() library function that could allow a local user to cause the system to hang, resulting in a denial-of-service condition. According to Sun, this only affects SPARC-based systems.

Impact

An unprivileged local user could cause the system to hang, resulting in a denial-of-service condition. In order to restore functionality, the system may need to be rebooted.

Solution

Apply Patch

Sun has issued an advisory to address this issue. For information on patches available for your system, please refer to the Sun Security Advisory.

Vendor Information

379390
 

Sun Microsystems Inc. Affected

Updated:  March 31, 2004

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

Please refer to Sun Alert ID: 57474.

If you have feedback, comments, or additional information about this vulnerability, please send us email.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was reported by Sun Microsystems Inc.

This document was written by Damon Morda.

Other Information

CVE IDs: None
Severity Metric: 2.64
Date Public: 2004-01-30
Date First Published: 2004-03-31
Date Last Updated: 2004-04-05 20:44 UTC
Document Revision: 10

Sponsored by CISA.