int(49)

Vulnerability Bulletins


Denegación de servicio en lockd de Solaris

Vulnerability classification

Property Value
Confidence level Oficial
Impact Denegación de Servicio
Dificulty Avanzado
Required attacker level Acceso remoto sin cuenta a un servicio exotico

System information

Property Value
Affected manufacturer UNIX
Affected software Sun Solaris 2.5.1
Sun Solaris 2.6
Sun Solaris 7.0
Sun Solaris 8.0
Sun Solaris 9.0

Description

Se ha descubierto una vulnerabilidad de denegación de servicio en el daemon lockd de Solaris.

La explotación de esta vulnerabilidad impedirá el establecimiento de conexiones NFS válidas.

Solution



Actualización de software

Solaris 2.5.1
Plataforma SPARC
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=103640&rev=42
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=104334&rev=02
Plataforma Intel
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=103641&rev=42
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=104335&rev=02

Sun Solaris 2.6
Plataforma SPARC
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=105181&rev=33
Plataforma Intel
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=105182&rev=33

Sun Solaris 7.0
Plataforma SPARC
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=106541&rev=23
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=109744&rev=02
Plataforma Intel
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=106542&rev=23
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=109745&rev=02

Sun Solaris 8.0
Plataforma SPARC
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=109783&rev=02
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=111321&rev=03
Plataforma Intel
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=109784&rev=02
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=111322&rev=03

Sun Solaris 9.0
Plataforma SPARC
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=113278&rev=01
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=113279&rev=01

Standar resources

Property Value
CVE CAN-2002-1228
BID

Other resources

Sun Alert Notification 47815
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F47815&zone_32=category%3Asecurity

Version history

Version Comments Date
1.0 Aviso emitido 2003-10-21
Ministerio de Defensa
CNI
CCN
CCN-CERT