Lucene search

K
certCERTVU:855635
HistoryFeb 05, 2003 - 12:00 a.m.

Sun Solaris lockd(1M) daemon vulnerable to DoS

2003-02-0500:00:00
www.kb.cert.org
12

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.003

Percentile

65.3%

Overview

A remotely exploitable denial-of-service vulnerability exists in the Solaris lockd(1M) daemon. Exploitation of this vulnerability may kill the lockd process.

Description

Sun Microsystems describes the lockd(1M) daemon as follows:

The lockd utility is part of the NFS lock manager, which supports record locking operations on NFS files. The lock manager provides two functions:

  * _it forwards fcntl(2) locking requests for NFS mounted file systems to the lock manager on the NFS server_
  * _it generates local file locking operations in response to requests forwarded from lock managers running on NFS client machines_

A vulnerability in the lockd(1M) daemon may allow a remote attacker to terminate the lockd(1M) process. A tool to exploit this vulnerability is publicly available.

Impact

A remote attacker can terminate the lockd(1M) daemon.


Solution

Apply a patch. For more information about the patches, please see Sun Alert Notification 47815.


Vendor Information

855635

Filter by status: All Affected Not Affected Unknown

Filter by content: __ Additional information available

__ Sort by: Status Alphabetical

Expand all

Javascript is disabled. Click here to view vendors.

Sun Microsystems Inc. __ Affected

Notified: August 16, 2002 Updated: February 05, 2003

Status

Affected

Vendor Statement

Sun confirms that this NFS Denial of Service does affect the following supported versions of Solaris:

Solaris 2.6, 7, 8, and 9

Patches are available for the above Solaris versions and are listed in Sun Alert 47815:

<http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fsalert/47815&gt;

Sun patches are available from:

<http://sunsolve.sun.com/securitypatch&gt;

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us [email](<mailto:[email protected]?Subject=VU%23855635 Feedback>).

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

The CERT/CC thanks Phil Moses of UC San Diego for reporting this vulnerability to us.

This document was written by Ian A Finlay.

Other Information

CVE IDs: CVE-2002-1228
Severity Metric: 8.10 Date Public:

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.003

Percentile

65.3%

Related for VU:855635