CVE-2010-0453: Input Validation
The ucodeioctl function in intel/io/ucodedrv.c in Sun Solaris 10 and OpenSolaris snv69 through snv133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODEGETVERSION IOCTL, which triggers a NULL pointer dereference in the ucodegetrev function, related to retrieval of the microcode revision.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0453?
The severity of CVE-2010-0453 is classified as medium due to its ability to cause a denial of service.
How do I fix CVE-2010-0453?
To fix CVE-2010-0453, you should update to a patched version of Sun Solaris or OpenSolaris that addresses this vulnerability.
Who is affected by CVE-2010-0453?
CVE-2010-0453 affects local users on Sun Solaris 10 and OpenSolaris snv_69 through snv_133, specifically on x86 architectures.
What impact does CVE-2010-0453 have on systems?
CVE-2010-0453 can trigger a system panic, resulting in a denial of service for affected systems.
Is there a workaround for CVE-2010-0453?
There is no widely known workaround for CVE-2010-0453; updating the software is the recommended approach.