Sun Solaris 10 UFS本地拒绝服务漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1111454 漏洞类型 其他
发布时间 2006-11-04 更新时间 2006-11-07
CVE编号 CVE-2006-5726 CNNVD-ID CNNVD-200611-076
漏洞平台 Solaris CVSS评分 4.9
|漏洞来源
https://www.exploit-db.com/exploits/28911
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200611-076
|漏洞详情
Solaris是一款由Sun开发和维护的商业性质UNIX操作系统。Solaris的文件系统实现在挂接恶意的分区时存在漏洞,攻击者可能利用此漏洞导致服务器崩溃。Solaris没有正确地处理UFS文件系统中被破坏的数据结构,攻击者通过诱骗用户加载特制的文件系统镜像导致系统崩溃,或破坏文件系统。
|漏洞EXP
source: http://www.securityfocus.com/bid/20919/info

Sun Solaris 10 is prone to a local denial-of-service vulnerability. This issue affects the UFS filesystem-handling code.

An attacker can exploit this issue to crash the affected computer, denying service to legitimate users.

Solaris 10 on the ia32/x86 architecture has been reported vulnerable; previous versions may be affected as well, but Symantec has not confirmed this.

https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/bin-sploits/28911.img.gz
|参考资料

来源:SECUNIA
名称:22714
链接:http://secunia.com/advisories/22714
来源:MISC
链接:http://projects.info-pull.com/mokb/MOKB-04-11-2006.html
来源:BID
名称:20919
链接:http://www.securityfocus.com/bid/20919
来源:VUPEN
名称:ADV-2006-4357
链接:http://www.frsirt.com/english/advisories/2006/4357