Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-1999-0908Solaris vulnerability

4 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
6.9%
top 8.57%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedSep 23
Latest updateApr 30

Description

Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDsun/solaris2.5.1, 2.6, 7.0+2
NVDsun/sunos5.5.1, 5.7+1

🔴Vulnerability Details

2
GHSA
GHSA-cxgc-8c6p-75xc: Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_ent2022-04-30
CVEList
CVE-1999-0908: Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_ent2000-03-22

💥Exploits & PoCs

1
Exploit-DB
Solaris 7.0 - Recursive mutex_enter Remote Panic (Denial of Service)1999-09-23
CVE-1999-0908 — SUN Solaris vulnerability | cvebase