7.1
CWE
399 476
Advisory Published
Updated

CVE-2009-3000: Null Pointer Dereference

First published: Fri Aug 28 2009(Updated: )

The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Network Cache Accelerator (NCA) logging is enabled, allows remote attackers to cause a denial of service (panic) via unspecified web-server traffic that triggers a NULL pointer dereference in the nl7c_http_log function, related to "improper http response handling."

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Solaris=snv_41
Solaris=snv_42
Solaris=snv_43
Solaris=snv_44
Solaris=snv_45
Solaris=snv_46
Solaris=snv_47
Solaris=snv_48
Solaris=snv_49
Solaris=snv_50
Solaris=snv_51
Solaris=snv_52
Solaris=snv_53
Solaris=snv_54
Solaris=snv_55
Solaris=snv_56
Solaris=snv_57
Solaris=snv_58
Solaris=snv_59
Solaris=snv_60
Solaris=snv_61
Solaris=snv_62
Solaris=snv_63
Solaris=snv_64
Solaris=snv_65
Solaris=snv_66
Solaris=snv_67
Solaris=snv_68
Solaris=snv_69
Solaris=snv_70
Solaris=snv_71
Solaris=snv_72
Solaris=snv_73
Solaris=snv_74
Solaris=snv_75
Solaris=snv_76
Solaris=snv_77
Solaris=snv_78
Solaris=snv_79
Solaris=snv_80
Solaris=snv_81
Solaris=snv_82
Solaris=snv_83
Solaris=snv_84
Solaris=snv_85
Solaris=snv_86
Solaris=snv_87
Solaris=snv_88
Solaris=snv_89
Solaris=snv_90
Solaris=snv_91
Solaris=snv_92
Solaris=snv_93
Solaris=snv_94
Solaris=snv_95
Solaris=snv_96
Solaris=snv_97
Solaris=snv_98
Solaris=snv_99
Solaris=snv_100
Solaris=snv_101
Solaris=snv_102
Solaris=snv_103
Solaris=snv_104
Solaris=snv_105
Solaris=snv_106
Solaris=snv_107
Solaris=snv_108
Solaris=snv_109
Solaris=snv_110
Solaris=snv_111
Solaris=snv_112
Solaris=snv_113
Solaris=snv_114
Solaris=snv_115
Solaris=snv_116
Solaris=snv_117
Solaris=snv_118
Solaris=snv_119
Solaris=snv_120
Solaris=snv_121
Solaris=snv_122
Oracle Solaris SPARC=10.0
Solaris=snv_41
Solaris=snv_42
Solaris=snv_43
Solaris=snv_44
Solaris=snv_45
Solaris=snv_46
Solaris=snv_47
Solaris=snv_48
Solaris=snv_49
Solaris=snv_50
Solaris=snv_51
Solaris=snv_52
Solaris=snv_53
Solaris=snv_54
Solaris=snv_55
Solaris=snv_56
Solaris=snv_57
Solaris=snv_58
Solaris=snv_59
Solaris=snv_60
Solaris=snv_61
Solaris=snv_62
Solaris=snv_63
Solaris=snv_64
Solaris=snv_65
Solaris=snv_66
Solaris=snv_67
Solaris=snv_68
Solaris=snv_69
Solaris=snv_70
Solaris=snv_71
Solaris=snv_72
Solaris=snv_73
Solaris=snv_74
Solaris=snv_75
Solaris=snv_76
Solaris=snv_77
Solaris=snv_78
Solaris=snv_79
Solaris=snv_80
Solaris=snv_81
Solaris=snv_82
Solaris=snv_83
Solaris=snv_84
Solaris=snv_85
Solaris=snv_86
Solaris=snv_87
Solaris=snv_88
Solaris=snv_89
Solaris=snv_90
Solaris=snv_91
Solaris=snv_92
Solaris=snv_93
Solaris=snv_94
Solaris=snv_95
Solaris=snv_96
Solaris=snv_97
Solaris=snv_98
Solaris=snv_99
Solaris=snv_100
Solaris=snv_101
Solaris=snv_102
Solaris=snv_104
Solaris=snv_105
Solaris=snv_106
Solaris=snv_107
Solaris=snv_108
Solaris=snv_109
Solaris=snv_110
Solaris=snv_111
Solaris=snv_112
Solaris=snv_113
Solaris=snv_114
Solaris=snv_115
Solaris=snv_116
Solaris=snv_117
Solaris=snv_118
Solaris=snv_119
Solaris=snv_120
Solaris=snv_121
Solaris=snv_122
Oracle Solaris SPARC=10.0

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2009-3000?

    CVE-2009-3000 has a severity rating that indicates it can lead to a denial of service due to a NULL pointer dereference in specific conditions.

  • What systems are affected by CVE-2009-3000?

    CVE-2009-3000 affects Sun Solaris 10 and OpenSolaris versions from snv_41 to snv_122 running on both SPARC and x86 architectures.

  • How do I fix CVE-2009-3000?

    To fix CVE-2009-3000, it is recommended to apply patches provided by the vendor for the affected versions of Solaris.

  • What type of vulnerability is CVE-2009-3000?

    CVE-2009-3000 is classified as a denial of service vulnerability.

  • Can CVE-2009-3000 be exploited remotely?

    Yes, CVE-2009-3000 can be exploited remotely through unspecified web-server traffic.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203