First published: Wed Jun 24 2009(Updated: )
Multiple memory leaks in the (1) IP and (2) IPv6 multicast implementation in the kernel in Sun Solaris 10, and OpenSolaris snv_67 through snv_93, allow local users to cause a denial of service (memory consumption) via vectors related to the association of (a) DL_ENABMULTI_REQ and (b) DL_DISABMULTI_REQ messages with ARP messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Solaris | =snv_67 | |
Solaris | =snv_68 | |
Solaris | =snv_69 | |
Solaris | =snv_70 | |
Solaris | =snv_71 | |
Solaris | =snv_72 | |
Solaris | =snv_73 | |
Solaris | =snv_74 | |
Solaris | =snv_75 | |
Solaris | =snv_76 | |
Solaris | =snv_77 | |
Solaris | =snv_78 | |
Solaris | =snv_79 | |
Solaris | =snv_80 | |
Solaris | =snv_81 | |
Solaris | =snv_82 | |
Solaris | =snv_83 | |
Solaris | =snv_84 | |
Solaris | =snv_85 | |
Solaris | =snv_86 | |
Solaris | =snv_87 | |
Solaris | =snv_88 | |
Solaris | =snv_89 | |
Solaris | =snv_90 | |
Solaris | =snv_91 | |
Solaris | =snv_92 | |
Solaris | =snv_93 | |
Oracle Solaris SPARC | =10.0 | |
Solaris | =snv_67 | |
Solaris | =snv_68 | |
Solaris | =snv_69 | |
Solaris | =snv_70 | |
Solaris | =snv_71 | |
Solaris | =snv_72 | |
Solaris | =snv_73 | |
Solaris | =snv_74 | |
Solaris | =snv_75 | |
Solaris | =snv_76 | |
Solaris | =snv_77 | |
Solaris | =snv_78 | |
Solaris | =snv_79 | |
Solaris | =snv_80 | |
Solaris | =snv_81 | |
Solaris | =snv_82 | |
Solaris | =snv_83 | |
Solaris | =snv_84 | |
Solaris | =snv_85 | |
Solaris | =snv_86 | |
Solaris | =snv_87 | |
Solaris | =snv_88 | |
Solaris | =snv_89 | |
Solaris | =snv_90 | |
Solaris | =snv_91 | |
Solaris | =snv_92 | |
Solaris | =snv_93 | |
Oracle Solaris SPARC | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2187 is rated as a moderate severity vulnerability due to its potential to lead to denial of service.
To mitigate CVE-2009-2187, updating the affected Solaris versions to a patched release is recommended.
CVE-2009-2187 affects multiple versions of Sun Solaris 10 and OpenSolaris from snv_67 to snv_93.
CVE-2009-2187 is a memory leak vulnerability in the IP and IPv6 multicast implementation.
CVE-2009-2187 can be exploited by local users to cause denial of service through excessive memory consumption.