CVE-2008-3666: High severity oracle solaris and zettabyte file system (zfs) vulnerability
Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a denial of service (panic) via a call to the sendfile system call, as reachable through the sendfilev library.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3666?
CVE-2008-3666 has a severity level that can lead to denial of service (panic) in affected systems.
Which systems are affected by CVE-2008-3666?
CVE-2008-3666 affects Sun Solaris 10 and OpenSolaris versions prior to snv_96, including multiple specific versions.
How do I fix CVE-2008-3666?
To address CVE-2008-3666, updating to a patched version of Solaris or OpenSolaris that resolves the issue is recommended.
What type of attacks can exploit CVE-2008-3666?
CVE-2008-3666 can be exploited by context-dependent attackers through the creation of crafted files and using the sendfilev system call.
What are the potential consequences of CVE-2008-3666?
Exploitation of CVE-2008-3666 can result in a denial of service, causing the affected system to panic.