Re: solaris DoS

From: plasmoid deep/thc/clb (plasmoidat_private)
Date: Fri Sep 24 1999 - 10:46:23 PDT

  • Next message: Marc SPARC: "[Fwd: Truth about ssh 1.2.27 vulnerabiltiy]"

    >Tested on Solaris 2.6 using a simple listen/accept server, as well as
    >with sendmail 8.9.3.
    
    I verified this DoS even on Solaris 2.7 Sparc and Solaris 2.7 Intel by
    using a service on a privilegded port (ssh2) and on a non-priviledged
    port (eggdrop-1.3.28).
    
    >I worked with Sun a while ago on this problem, and they have released
    >patch 105529-07 (for sparc) and 105530 (for x86).  According to the patch
    >readme, the problem is with a recursive mutex_enter on the TCP streams
    >driver.
    
    I was unable to find patches for the Solaris 2.7 edition, i can only hope
    they exist and I was too stoned to find them.
    
    regards,
    plasmoid
    
    _______________________________________________________________________________
    [THC]  The Hacker`s Choice - Internet & Communication Security - thc.pimmel.com
    get my public PGP key for any mailexchange: [ finger plasmoidat_private ]
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:05:09 PDT