CVE-2009-0346Opensolaris vulnerability

CWE-3103 documents3 sources
Severity
4.9MEDIUMNVD
EPSS
0.0%
top 86.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 29
Latest updateMay 2

Description

The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.

CVSS vector

AV:L/AC:L/C:N/I:N/A:CExploitability: 3.9 | Impact: 6.9

Affected Packages2 packages

NVDsun/opensolaris93 versions+92
NVDsun/solaris10, 9+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2mcr-hvvf-8r3g: The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85,2022-05-02
CVEList
CVE-2009-0346: The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85,2009-01-29
CVE-2009-0346 — SUN Opensolaris vulnerability | cvebase