First published: Tue Apr 23 2019(Updated: )
Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: File Locking Services). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.0 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris and Zettabyte File System (ZFS) | =11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2577 is rated as a high severity vulnerability.
To fix CVE-2019-2577, you should apply the latest patches provided by Oracle for Oracle Solaris 11.
CVE-2019-2577 affects users of Oracle Solaris 11 with File Locking Services that are not patched.
CVE-2019-2577 can be exploited by low privileged attackers who have logged on to the Oracle Solaris infrastructure.
Exploitation of CVE-2019-2577 may lead to unauthorized access and manipulation of file locking services.