Secunia SmallBusiness
Overview
Advisories
Research
Forums
Create Profile
Our Commitment
Database
Search
Advisories by Product
Advisories by Vendor
Terminology
Report Vulnerability
Insecure Library Loading

Secunia Advisory SA50911

Oracle Solaris Multiple Vulnerabilities
Secunia Advisory SA50911
Secunia VIM 4.0 - Free Trial
Release Date 2012-10-17
   
Popularity 974 views
Comments 0 comments

Criticality level Highly criticalHighly critical
Impact Hijacking
Manipulation of data
Exposure of sensitive information
Privilege escalation
DoS
System access
Where From remote
Authentication level This information is available to Secunia VIM customers
   
Report reliability This information is available to Secunia VIM customers
Solution Status Vendor Patch
   
Systems affected This information is available to Secunia VIM customers
Approve distribution This information is available to Secunia VIM customers
Remediation status Secunia CSI, Secunia PSI
Automated scanning Secunia CSI, Secunia PSI
   
Operating System
Oracle Solaris 11.x
Sun Solaris 10.x
Sun Solaris 8.x
Sun Solaris 9.x

Secunia CVSS Score This information is available to Secunia VIM Customers
CVE Reference(s) CVE-2011-0719 CVSS score available to Secunia VIM customers
CVE-2011-4128 CVSS score available to Secunia VIM customers
CVE-2012-0217 CVSS score available to Secunia VIM customers
CVE-2012-1182 CVSS score available to Secunia VIM customers
CVE-2012-1573 CVSS score available to Secunia VIM customers
CVE-2012-2812 CVSS score available to Secunia VIM customers
CVE-2012-2813 CVSS score available to Secunia VIM customers
CVE-2012-2814 CVSS score available to Secunia VIM customers
CVE-2012-2836 CVSS score available to Secunia VIM customers
CVE-2012-2837 CVSS score available to Secunia VIM customers
CVE-2012-2840 CVSS score available to Secunia VIM customers
CVE-2012-2841 CVSS score available to Secunia VIM customers
CVE-2012-2845 CVSS score available to Secunia VIM customers
CVE-2012-3165 CVSS score available to Secunia VIM customers
CVE-2012-3187 CVSS score available to Secunia VIM customers
CVE-2012-3189 CVSS score available to Secunia VIM customers
CVE-2012-3199 CVSS score available to Secunia VIM customers
CVE-2012-3203 CVSS score available to Secunia VIM customers
CVE-2012-3204 CVSS score available to Secunia VIM customers
CVE-2012-3207 CVSS score available to Secunia VIM customers
CVE-2012-3208 CVSS score available to Secunia VIM customers
CVE-2012-3209 CVSS score available to Secunia VIM customers
CVE-2012-3210 CVSS score available to Secunia VIM customers
CVE-2012-3211 CVSS score available to Secunia VIM customers
CVE-2012-3212 CVSS score available to Secunia VIM customers
CVE-2012-3215 CVSS score available to Secunia VIM customers
CVE-2012-3401 CVSS score available to Secunia VIM customers
CVE-2012-5095 CVSS score available to Secunia VIM customers
  

Description

A weakness and multiple vulnerabilities have been reported in Oracle Solaris, which can be exploited by malicious, local users to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and gain escalated privileges, by malicious users to cause a DoS and potentially compromise a vulnerable system, and by malicious people to disclose certain sensitive information, hijack a user's session, cause a DoS and compromise a vulnerable system.

For more information:
SA43512
SA46770
SA48488 (#1)
SA48742
SA49857
SA49938 (#1)
SA50235
SA50544

1) An unspecified error within the kernel subcomponent can be exploited to cause a hang or frequently repeatable crash.

2) An unspecified error within the COMSTAR subcomponent can be exploited to cause a hang or frequently repeatable crash.

3) An unspecified error exists within the Gnome Trusted Extension subcomponent.

4) An unspecified error exists within the kernel subcomponent.

5) An unspecified error exists within the Power Management subcomponent.

6) An unspecified error exists within the kernel subcomponent.

7) An unspecified error within the Logical Domain(LDOM) subcomponent can be exploited to cause a hang or frequently repeatable crash or update, insert, or delete some Solaris accessible data.

Note: This vulnerability only affects Solaris running on SPARC.

8) An unspecified error within the kernel subcomponent can be exploited to cause a hang or frequently repeatable crash.

9) An unspecified error within the kernel/RCTL subcomponent can be exploited to cause a hang or frequently repeatable crash.

10) An unspecified error within the kernel subcomponent can be exploited to cause a hang or frequently repeatable crash.

Note: This vulnerability only affects Solaris running on SPARC T4 servers.

11) An unspecified error within the kernel/System Call subcomponent can be exploited to cause a hang or frequently repeatable crash.

12) An unspecified error exists within the inetd subcomponent.

13) An unspecified error within the mailx subcomponent can be exploited to read, update, insert, or delete some Solaris accessible data.

14) An unspecified error within the Gnome Display Manager(GDM) subcomponent can be exploited to cause a hang or frequently repeatable crash.

15) An unspecified error within the Vino server subcomponent can be exploited to update, insert, or delete some Solaris accessible data.

16) An unspecified error exists within the kernel subcomponent.

Note: This vulnerability only affects Solaris running on SPARC.

Please see the vendor's advisories for a list of affected versions.


Solution
Apply updates (please see the vendor's advisories for details).

Provided and/or discovered by
It is currently unclear who reported the vulnerabilities as the Oracle Critical Patch Update for October 2012 only provides a bundled list of credits. This section will be updated when/if the original reporter provides more information.

Original Advisory
Oracle:
http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html#AppendixSUNS
https://blogs.oracle.com/sunsecurity/entry/cve_2011_0719_denial_of
https://blogs.oracle.com/sunsecurity/entry/cve_2011_4128_buffer_overflow
https://blogs.oracle.com/sunsecurity/entry/cve_2012_1182_arbitrary_code
https://blogs.oracle.com/sunsecurity/entry/cve_2012_1573_denial_of
https://blogs.oracle.com/sunsecurity/entry/cve_2012_3401_denial_of
https://blogs.oracle.com/sunsecurity/entry/cve_2012_3524_permissions_privileges
https://blogs.oracle.com/sunsecurity/entry/cve_2012_4245_arbitrary_code
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_libexif1

Other references
Further details available to Secunia VIM customers

Deep Links
Links available to Secunia VIM customers


Do you have additional information related to this advisory?

Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com

Subject: Oracle Solaris Multiple Vulnerabilities
 
No posts yet

-

You must be logged in to post a comment.




 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2013 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability