First published: Wed Nov 25 2009(Updated: )
Unspecified vulnerability in the timeout mechanism in sshd in Sun Solaris 10, and OpenSolaris snv_99 through snv_123, allows remote attackers to cause a denial of service (daemon outage) via unknown vectors that trigger a "dangling sshd authentication thread."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Solaris | =snv_113 | |
Solaris | =snv_114 | |
Solaris | =snv_101 | |
Solaris | =snv_120 | |
Solaris | =snv_110 | |
Solaris | =snv_116 | |
Solaris | =snv_120 | |
Solaris | =snv_117 | |
Solaris | =snv_123 | |
Solaris | =snv_104 | |
Solaris | =snv_103 | |
Solaris | =snv_118 | |
Solaris | =snv_105 | |
Solaris | =snv_119 | |
Solaris | =snv_114 | |
Solaris | =snv_121 | |
Solaris | =snv_103 | |
Solaris | =snv_121 | |
Solaris | =snv_106 | |
Solaris | =snv_106 | |
Solaris | =snv_119 | |
Solaris | =snv_100 | |
Solaris | =snv_107 | |
Solaris | =snv_112 | |
Oracle Solaris SPARC | =10 | |
Solaris | =snv_112 | |
Solaris | =snv_123 | |
Solaris | =snv_99 | |
Solaris | =snv_107 | |
Solaris | =snv_115 | |
Solaris | =snv_100 | |
Solaris | =snv_122 | |
Solaris | =snv_115 | |
Solaris | =snv_111 | |
Solaris | =snv_109 | |
Solaris | =snv_113 | |
Solaris | =snv_108 | |
Solaris | =snv_102 | |
Solaris | =snv_105 | |
Solaris | =snv_108 | |
Solaris | =snv_122 | |
Solaris | =snv_116 | |
Solaris | =snv_104 | |
Solaris | =snv_101 | |
Solaris | =snv_117 | |
Solaris | =snv_99 | |
Solaris | =snv_109 | |
Solaris | =snv_102 | |
Solaris | =snv_111 | |
Oracle Solaris SPARC | =10 | |
Solaris | =snv_110 | |
Solaris | =snv_118 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4075 is classified as a denial of service vulnerability that can impact availability.
To fix CVE-2009-4075, update the affected Sun Solaris or OpenSolaris system to a patched version provided by the vendor.
CVE-2009-4075 affects various versions of Sun Solaris 10 and OpenSolaris, including SNV versions from 99 to 123.
CVE-2009-4075 enables remote attackers to cause a denial of service by triggering a dangling sshd authentication thread.
CVE-2009-4075 has been noted to have unspecified vectors for exploitation leading to service outages.