CVE-2009-3100: Medium severity oracle solaris and zettabyte file system (zfs) vulnerability
xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv109 through snv122, and X11 6.4.1 on Solaris 8 does not properly handle Accessibility support, which allows local users to cause a denial of service (system hang) by locking the screen and then attempting to launch an Accessibility pop-up window, related to a regression in certain Solaris and OpenSolaris patches.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3100?
CVE-2009-3100 is classified as a medium severity vulnerability that can lead to a denial of service.
How do I fix CVE-2009-3100?
To fix CVE-2009-3100, apply the latest patches from your operating system vendor for Solaris.
What systems are affected by CVE-2009-3100?
CVE-2009-3100 affects Sun Solaris 8, 9, and 10, as well as OpenSolaris from snv_109 to snv_122.
What type of vulnerability is CVE-2009-3100?
CVE-2009-3100 is a denial of service vulnerability in the xscreensaver component.
Can CVE-2009-3100 be exploited remotely?
CVE-2009-3100 can only be exploited locally by a user who can lock the screen.