Security Advisory

CVE-2008-3666

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2008-08-13 17:00:00
Last updated 2024-08-07 09:45:19
Assigner mitre
State PUBLISHED

Description

Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a denial of service (panic) via a call to the sendfile system call, as reachable through the sendfilev library.