CVE-2009-0838: Medium severity Sun OpenSolaris vulnerability
Published Mar 6, 2009
·Updated
The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv88 through snv102, does not properly free memory, which allows local users to cause a denial of service (panic) via unspecified vectors, related to the vmemhashdelete function.
Affected Software
40 affected components
Sun OpenSolaris=snv_101
Sun OpenSolaris=snv_93
Sun OpenSolaris=snv_91
Sun OpenSolaris=snv_92
Sun OpenSolaris=snv_101b
Sun OpenSolaris=snv_88
Sun OpenSolaris=snv_93
Sun OpenSolaris=snv_94
Sun OpenSolaris=snv_100
Sun OpenSolaris=snv_90-x86
Sun OpenSolaris=snv_89
Sun OpenSolaris=snv_90
Sun OpenSolaris=snv_96
Sun OpenSolaris=snv_99
Sun OpenSolaris=snv_97
Sun SunOS=5.10
Sun OpenSolaris=snv_100
Sun OpenSolaris=snv_88
Sun OpenSolaris=snv_96
Sun OpenSolaris=snv_94
Sun OpenSolaris=snv_98
Sun OpenSolaris=snv_98
Sun OpenSolaris=snv_91
Sun OpenSolaris=snv_95
Sun OpenSolaris=snv_102
Sun OpenSolaris=snv_92
Sun OpenSolaris=snv_95
Sun OpenSolaris=snv_95
Sun OpenSolaris=snv_93
Sun OpenSolaris=snv_88
Sun OpenSolaris=snv_92
Sun OpenSolaris=snv_94
Sun OpenSolaris=snv_101
Sun OpenSolaris=snv_90
Sun OpenSolaris=snv_97
Sun OpenSolaris=snv_99
Sun OpenSolaris=snv_102
Sun OpenSolaris=snv_91
Sun OpenSolaris=snv_89
Sun OpenSolaris=snv_89
Remediation
Event History
Mar 6, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0838?
CVE-2009-0838 is classified as a medium-severity vulnerability that can lead to a denial of service.
2
How do I fix CVE-2009-0838?
To fix CVE-2009-0838, update your system to a patched version of Solaris that addresses this memory management issue.
3
Which systems are affected by CVE-2009-0838?
CVE-2009-0838 affects Sun Solaris 10 and OpenSolaris versions snv_88 through snv_102.
4
What type of attack does CVE-2009-0838 allow?
CVE-2009-0838 allows local users to cause a denial of service by triggering a system panic.
5
What component is responsible for CVE-2009-0838?
CVE-2009-0838 is caused by improper memory handling in the crypto pseudo device driver.