The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
Link | Tags |
---|---|
http://sunsolve.sun.com/search/document.do?assetkey=1-66-240086-1 | patch vendor advisory |
http://secunia.com/advisories/33727 | third party advisory |
http://sunsolve.sun.com/search/document.do?assetkey=1-21-114344-38-1 | patch |
http://support.avaya.com/elmodocs2/security/ASA-2009-043.htm | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6088 | vdb entry signature |
https://exchange.xforce.ibmcloud.com/vulnerabilities/48328 | vdb entry |
http://www.vupen.com/english/advisories/2009/0365 | vdb entry |
http://www.securityfocus.com/bid/33504 | vdb entry |