CVE-2009-0838Opensolaris vulnerability

CWE-3993 documents3 sources
Severity
4.9MEDIUMNVD
EPSS
0.1%
top 81.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 6
Latest updateMay 2

Description

The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to cause a denial of service (panic) via unspecified vectors, related to the vmem_hash_delete function.

CVSS vector

AV:L/AC:L/C:N/I:N/A:CExploitability: 3.9 | Impact: 6.9

Affected Packages2 packages

NVDsun/opensolaris16 versions+15
NVDsun/sunos5.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xgpw-5ww4-gfq7: The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to2022-05-02
CVEList
CVE-2009-0838: The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to2009-03-06
CVE-2009-0838 — SUN Opensolaris vulnerability | cvebase