Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-3870

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2008-3870
Last Modified 21 Aug 2010 01:23:24
Published 26 May 2009 05:30:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-3870

Summary

Integer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request that triggers a heap-based buffer overflow, related to improper memory allocation.

Vulnerable Systems

Operating System

  • Sun Solaris 8.0

  • Sun Solaris 9.0


References

SUNALERT - 259468

CONFIRM - http://sunsolve.sun.com/search/document.do?assetkey=1-21-116455-02-1

XF - solaris-allocating-bo(50706)

VUPEN - ADV-2009-1409

SECTRACK - 1022275

BID - 35083

BUGTRAQ - 20090523 Secunia Research: Sun Solaris "sadmind" Integer Overflow Vulnerability

OSVDB - 54668

CONFIRM - http://support.avaya.com/elmodocs2/security/ASA-2009-195.htm

MISC - http://secunia.com/secunia_research/2008-47/

SECUNIA - 35191

SECUNIA - 32473


Last Updated: 27 May 2016 10:48:20