First published: Fri Aug 08 2008(Updated: )
Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris and Zettabyte File System (ZFS) | =8 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9 | |
Oracle Solaris and Zettabyte File System (ZFS) | <=build_snv_95 | |
Oracle Solaris and Zettabyte File System (ZFS) | =build_snv_89 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9 | |
Oracle Solaris and Zettabyte File System (ZFS) | =build_snv_19 | |
Oracle Solaris and Zettabyte File System (ZFS) | =build_snv_01 | |
Oracle Solaris and Zettabyte File System (ZFS) | =build_snv_92 | |
Oracle Solaris and Zettabyte File System (ZFS) | =build_snv_88 | |
Oracle Solaris and Zettabyte File System (ZFS) | =8 | |
Sun SunOS | =5.8 | |
Oracle Solaris and Zettabyte File System (ZFS) | =10 | |
Oracle Solaris and Zettabyte File System (ZFS) | =build_snv_22 | |
Oracle Solaris and Zettabyte File System (ZFS) | ||
Sun SunOS | =5.10 | |
Sun SunOS | =5.9 | |
Oracle Solaris and Zettabyte File System (ZFS) | =build_snv_91 | |
Oracle Solaris and Zettabyte File System (ZFS) | ||
Oracle Solaris and Zettabyte File System (ZFS) | =build_snv_02 | |
Oracle Solaris and Zettabyte File System (ZFS) | =build_snv_64 | |
Oracle Solaris and Zettabyte File System (ZFS) | =10 | |
Oracle Solaris and Zettabyte File System (ZFS) | ||
Oracle Solaris and Zettabyte File System (ZFS) | =build_snv_13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0965 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2008-0965, apply the latest patches available for your version of Solaris or OpenSolaris.
CVE-2008-0965 affects Sun Solaris versions 8 to 10 and OpenSolaris builds prior to snv_96.
Yes, CVE-2008-0965 can be exploited remotely through crafted SMB packets.
Exploitation of CVE-2008-0965 can lead to arbitrary code execution on the vulnerable system.