Vulnerability Development mailing list archives

Re: solaris DoS (fwd)


From: rmukerji () EXECPC COM (Arindum Mukerji)
Date: Thu, 7 Oct 1999 11:43:28 -0500


Hi,

* Drazen Kacar (dave () SRCE HR) [991007 10:19]:
I have confirmed this DOES work on Solaris 2.6 105181-16.

Hmm. I just tried on another host with 105181-14 and it crashed. Then I
installed the current recommended patch set (which has 105181-16) and
it doesn't crash any more. Perhaps another patch (TCP, most likely)
is relevant. Prior to patching, that host had a fairly old revision of
tcp patch.


You are correct in the assumption that this bug is not fixed in a
kernel jumbo patch. It is fixed in the /kernel/drv/tcp patch.

The revision it's corrected in is 105529-07. The current version
is 105529-08, which fixes some additional problems with a panic
due to a null pointer dereference under certain circumstances.

For 5.6 x86, this patch is available as 105530-08.

Regards,

--
Arindum



Current thread: