SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Generic)  >   Sun Management Center (SunMC) Vendors:   Sun
Sun Management Center (SunMC) Bug in PRM Module Lets Remote Users Deny Service
SecurityTracker Alert ID:  1020890
SecurityTracker URL:  http://securitytracker.com/id/1020890
CVE Reference:   CVE-2008-4117   (Links to External Site)
Updated:  Sep 25 2008
Original Entry Date:  Sep 16 2008
Impact:   Denial of service via network
Fix Available:  Yes  Vendor Confirmed:  Yes  Exploit Included:  Yes  
Version(s): 3.6.1, 4.0
Description:   A vulnerability was reported in Sun Management Center (SunMC). A remote user can cause denial of service conditions.

A remote user can supply a null username and null password value to the PRM web page to consume excessive memory on the target system, causing the target system to become unusable.

The PRM module is only affected when SunMC is installed with the PRM module.

Impact:   A remote user can consume excessive memory on the target system.
Solution:   The vendor has issued a fix.

SPARC Platform

* SunMC 3.6.1 (for Solaris 8) with patch 125191-02 or later
* SunMC 3.6.1 (for Solaris 9) with patch 125192-02 or later
* SunMC 3.6.1 (for Solaris 10) with patch 125194-02 or later
* SunMC 4.0 (for Solaris 10) with patch 138553-02 or later

x86 Platform

* SunMC 4.0 (for Solaris 10_x86) with patch 138554-02 or later

The vendor's advisory is available at:

http://sunsolve.sun.com/search/document.do?assetkey=1-66-241686-1

Vendor URL:  sunsolve.sun.com/search/document.do?assetkey=1-66-241686-1 (Links to External Site)
Cause:   Exception handling error
Underlying OS:  UNIX (Solaris - SunOS)

Message History:   None.


 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2020, SecurityGlobal.net LLC