Sun Solaris Can Be Crashed By a Remote User Sending a Flood of ARP Packets
|
|
SecurityTracker Alert ID: 1013179
|
|
SecurityTracker URL: http://securitytracker.com/id?1013179
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Feb 15 2005
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): Solaris 7, 8, and 9
|
Description: A vulnerability was reported in Sun Solaris in the processing of ARP packets. A remote user can cause denial of service conditions.
A remote user on a local network can send a large number of specific ARP packets to cause the target system to hang.
Solaris 7, 8, and 9 are affected.
|
Impact: A remote user can cause the kernel to hang.
|
Solution: Sun has issued the following fixes:
SPARC Platform
Solaris 7 with patch 106541-39 or later
Solaris 8 with patch 116965-05
or later
Solaris 9 with patch 114344-09 or later
x86 Platform
Solaris 7 with patch 106542-39 or later
Solaris 8 with
patch 116966-05 or later
Solaris 9 with patch 114345-08 or later
|
Vendor URL: classic.sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57673 (Links to External Site)
|
Cause: Exception handling error
|
Underlying OS: UNIX (Solaris - SunOS)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 14 Feb 2005 20:27:37 -0500
Subject: http://classic.sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57673&zone_32
|
> A system receiving a very large number of specific arp(7P) network packets (an "arp
> storm" or "arp hurricane") could cause the system to hang. These ARP packets coul d
> result from a remote privileged user implementing a Denial of Service (DoS) or from
> a misconfigured (or broken) router inadvertently sending the packets.
Solaris 7, 8, and 9 are affected.
Sun has issued the following fixes:
SPARC Platform
Solaris 7 with patch 106541-39 or later
Solaris 8 with patch 116965-05 or later
Solaris 9 with patch 114344-09 or later
x86 Platform
Solaris 7 with patch 106542-39 or later
Solaris 8 with patch 116966-05 or later
Solaris 9 with patch 114345-08 or later
-----
Sun Alert ID: 57673
Synopsis: Security Vulnerability With ARP Handling Could Cause System to Hang
Category: Security, Availability
Product: Solaris
BugIDs: 4653899
Avoidance: Patch, Workaround
State: Resolved
Date Released: 11-Feb-2005
Date Closed: 11-Feb-2005
Date Modified:
|
|