Vulnerability Name:

CVE-2008-5661 (CCN-47378)

Assigned:2008-12-15
Published:2008-12-15
Updated:2017-08-08
Summary:The IPv4 Forwarding feature in Sun Solaris 10 and OpenSolaris snv_47 through snv_82, with certain patches installed, allows remote attackers to cause a denial of service (panic) via unknown vectors that trigger a NULL pointer dereference.
Per http://sunsolve.sun.com/search/document.do?assetkey=1-26-241126-1

"Note 3: A system is only affected by this issue if it is configured to use IPv4, has a network route with a gateway of 127.0.0.1, and the route does not have the blackhole flag set."
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.4 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C)
4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2008-5661

Source: CCN
Type: SA33148
Sun Solaris IPv4 Forwarding Denial of Service

Source: SECUNIA
Type: Vendor Advisory
33148

Source: CCN
Type: SECTRACK ID: 1021413
Solaris IPv4 Forwarding Bug Lets Remote Users Deny Service

Source: SUNALERT
Type: Patch, Vendor Advisory
241126

Source: CCN
Type: Sun Alert ID: 241126
A Security Vulnerability in IPv4 Forwarding may Allow a Remote User to Panic the System

Source: CCN
Type: ASA-2008-519
A Security Vulnerability in IPv4 Forwarding may Allow a Remote User to Panic the System (Sun 241126)

Source: CCN
Type: OSVDB ID: 50828
Solaris IPv4 Forwarding Unspecified NULL Dereference Remote DoS

Source: BID
Type: UNKNOWN
32861

Source: CCN
Type: BID-32861
Sun Solaris IPv4 Forwarding Denial of Service Vulnerability

Source: SECTRACK
Type: UNKNOWN
1021413

Source: XF
Type: UNKNOWN
solaris-ipv4-forwarding-dos(47378)

Source: XF
Type: UNKNOWN
solaris-ipv4-forwarding-dos(47378)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:sun:opensolaris:snv_47:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_47:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_48:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_48:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_49:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_49:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_50:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_50:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_51:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_51:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_52:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_52:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_53:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_53:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_54:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_54:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_55:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_55:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_56:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_56:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_57:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_57:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_58:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_58:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_59:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_59:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_60:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_60:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_61:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_61:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_62:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_62:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_63:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_63:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_64:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_64:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_65:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_65:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_66:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_66:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_67:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_67:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_68:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_68:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_69:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_69:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_70:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_70:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_71:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_71:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_72:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_72:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_73:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_73:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_74:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_74:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_75:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_75:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_76:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_76:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_77:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_77:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_78:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_78:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_79:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_79:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_80:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_80:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_81:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_81:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_82:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_82:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10:*:x86:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:sun:solaris:10::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_47::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_64::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_47::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_64::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_48::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_50::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_53::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_54::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_56::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_58::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_59::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_60::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_62::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_65::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_68::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_69::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_72::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_75::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_76::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_78::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_81::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_82::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_49::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_51::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_52::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_55::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_57::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_61::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_63::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_66::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_67::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_70::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_71::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_73::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_74::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_77::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_79::x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_48::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_55::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_54::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_50::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_57::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_49::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_56::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_52::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_51::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_53::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_67::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_66::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_59::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_65::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_58::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_61::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_63::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_60::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_62::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_71::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_68::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_72::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_77::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_70::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_74::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_73::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_76::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_69::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_75::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_78::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_79::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_80::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_82::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_81::sparc:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:build_snv_80::x86:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sun opensolaris snv_47
    sun opensolaris snv_47
    sun opensolaris snv_48
    sun opensolaris snv_48
    sun opensolaris snv_49
    sun opensolaris snv_49
    sun opensolaris snv_50
    sun opensolaris snv_50
    sun opensolaris snv_51
    sun opensolaris snv_51
    sun opensolaris snv_52
    sun opensolaris snv_52
    sun opensolaris snv_53
    sun opensolaris snv_53
    sun opensolaris snv_54
    sun opensolaris snv_54
    sun opensolaris snv_55
    sun opensolaris snv_55
    sun opensolaris snv_56
    sun opensolaris snv_56
    sun opensolaris snv_57
    sun opensolaris snv_57
    sun opensolaris snv_58
    sun opensolaris snv_58
    sun opensolaris snv_59
    sun opensolaris snv_59
    sun opensolaris snv_60
    sun opensolaris snv_60
    sun opensolaris snv_61
    sun opensolaris snv_61
    sun opensolaris snv_62
    sun opensolaris snv_62
    sun opensolaris snv_63
    sun opensolaris snv_63
    sun opensolaris snv_64
    sun opensolaris snv_64
    sun opensolaris snv_65
    sun opensolaris snv_65
    sun opensolaris snv_66
    sun opensolaris snv_66
    sun opensolaris snv_67
    sun opensolaris snv_67
    sun opensolaris snv_68
    sun opensolaris snv_68
    sun opensolaris snv_69
    sun opensolaris snv_69
    sun opensolaris snv_70
    sun opensolaris snv_70
    sun opensolaris snv_71
    sun opensolaris snv_71
    sun opensolaris snv_72
    sun opensolaris snv_72
    sun opensolaris snv_73
    sun opensolaris snv_73
    sun opensolaris snv_74
    sun opensolaris snv_74
    sun opensolaris snv_75
    sun opensolaris snv_75
    sun opensolaris snv_76
    sun opensolaris snv_76
    sun opensolaris snv_77
    sun opensolaris snv_77
    sun opensolaris snv_78
    sun opensolaris snv_78
    sun opensolaris snv_79
    sun opensolaris snv_79
    sun opensolaris snv_80
    sun opensolaris snv_80
    sun opensolaris snv_81
    sun opensolaris snv_81
    sun opensolaris snv_82
    sun opensolaris snv_82
    sun solaris 10
    sun solaris 10
    sun solaris 10
    sun solaris 10
    sun opensolaris build_snv_47
    sun opensolaris build_snv_64
    sun opensolaris build_snv_47
    sun opensolaris build_snv_64
    sun opensolaris build_snv_48
    sun opensolaris build_snv_50
    sun opensolaris build_snv_53
    sun opensolaris build_snv_54
    sun opensolaris build_snv_56
    sun opensolaris build_snv_58
    sun opensolaris build_snv_59
    sun opensolaris build_snv_60
    sun opensolaris build_snv_62
    sun opensolaris build_snv_65
    sun opensolaris build_snv_68
    sun opensolaris build_snv_69
    sun opensolaris build_snv_72
    sun opensolaris build_snv_75
    sun opensolaris build_snv_76
    sun opensolaris build_snv_78
    sun opensolaris build_snv_81
    sun opensolaris build_snv_82
    sun opensolaris build_snv_49
    sun opensolaris build_snv_51
    sun opensolaris build_snv_52
    sun opensolaris build_snv_55
    sun opensolaris build_snv_57
    sun opensolaris build_snv_61
    sun opensolaris build_snv_63
    sun opensolaris build_snv_66
    sun opensolaris build_snv_67
    sun opensolaris build_snv_70
    sun opensolaris build_snv_71
    sun opensolaris build_snv_73
    sun opensolaris build_snv_74
    sun opensolaris build_snv_77
    sun opensolaris build_snv_79
    sun opensolaris build_snv_48
    sun opensolaris build_snv_55
    sun opensolaris build_snv_54
    sun opensolaris build_snv_50
    sun opensolaris build_snv_57
    sun opensolaris build_snv_49
    sun opensolaris build_snv_56
    sun opensolaris build_snv_52
    sun opensolaris build_snv_51
    sun opensolaris build_snv_53
    sun opensolaris build_snv_67
    sun opensolaris build_snv_66
    sun opensolaris build_snv_59
    sun opensolaris build_snv_65
    sun opensolaris build_snv_58
    sun opensolaris build_snv_61
    sun opensolaris build_snv_63
    sun opensolaris build_snv_60
    sun opensolaris build_snv_62
    sun opensolaris build_snv_71
    sun opensolaris build_snv_68
    sun opensolaris build_snv_72
    sun opensolaris build_snv_77
    sun opensolaris build_snv_70
    sun opensolaris build_snv_74
    sun opensolaris build_snv_73
    sun opensolaris build_snv_76
    sun opensolaris build_snv_69
    sun opensolaris build_snv_75
    sun opensolaris build_snv_78
    sun opensolaris build_snv_79
    sun opensolaris build_snv_80
    sun opensolaris build_snv_82
    sun opensolaris build_snv_81
    sun opensolaris build_snv_80