CVE-2009-2644Race Condition in Opensolaris

CWE-362Race Condition3 documents3 sources
Severity
4.9MEDIUMNVD
EPSS
0.0%
top 85.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 29
Latest updateMay 2

Description

Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allows local users to cause a denial of service (panic) via vectors related to "pathnames for invalid fds."

CVSS vector

AV:L/AC:L/C:N/I:N/A:CExploitability: 3.9 | Impact: 6.9

Affected Packages2 packages

NVDsun/opensolaris121 versions+120
NVDsun/solaris10.0, 9.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7c58-65v4-hw6h: Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allow2022-05-02
CVEList
CVE-2009-2644: Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allow2009-07-29
CVE-2009-2644 — Race Condition in SUN Opensolaris | cvebase