Vulnerability Name:

CVE-2008-5684 (CCN-47311)

Assigned:2008-12-12
Published:2008-12-12
Updated:2017-09-29
Summary:Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 through 10 and OpenSolaris before snv_85 allows context-dependent attackers to cause a denial of service (application crash), as demonstrated by a port scan that triggers a segmentation violation in the Gnome session manager (aka gnome-session).
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2008-5684

Source: CCN
Type: SA33157
Sun Solaris "libICE" Denial of Service Vulnerability

Source: SECUNIA
Type: Vendor Advisory
33157

Source: CCN
Type: SA33325
Avaya CMS Solaris "libICE" Denial of Service Vulnerability

Source: SECUNIA
Type: UNKNOWN
33325

Source: CCN
Type: SECTRACK ID: 1021391
libICE Lets Local or Remote Users Deny Service

Source: SECTRACK
Type: UNKNOWN
1021391

Source: CONFIRM
Type: Patch
http://sunsolve.sun.com/search/document.do?assetkey=1-21-119067-11-1

Source: SUNALERT
Type: Patch, Vendor Advisory
243566

Source: CCN
Type: Sun Alert ID: 243566
Security Vulnerability in the X Inter Client Exchange Library (libICE) Shipped With Solaris May Allow a Denial of Service (DoS)

Source: MISC
Type: UNKNOWN
http://support.avaya.com/elmodocs2/security/ASA-2008-513.htm

Source: CCN
Type: ASA-2008-513
Security Vulnerability in the X Inter Client Exchange Library (libICE) Shipped With Solaris May Allow a Denial of Service (DoS) (Sun 243566)

Source: CCN
Type: OSVDB ID: 52532
Solaris X Inter Client Exchange library (aka libICE) Port Scan DoS

Source: BID
Type: UNKNOWN
32807

Source: CCN
Type: BID-32807
Sun Solaris 'libICE' Unspecified Denial of Service Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2008-3431

Source: XF
Type: UNKNOWN
sun-solaris-libice-dos(47311)

Source: XF
Type: UNKNOWN
sun-solaris-libice-dos(47311)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:6003

Vulnerable Configuration:Configuration 1:
  • cpe:/o:sun:opensolaris:snv_01:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_02:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_03:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_04:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_05:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_06:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_07:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_08:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_09:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_10:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_11:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_12:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_13:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_14:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_15:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_16:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_17:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_18:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_19:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_20:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_21:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_22:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_23:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_24:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_25:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_26:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_27:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_28:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_29:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_30:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_31:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_32:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_33:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_34:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_35:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_36:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_37:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_38:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_39:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_40:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_41:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_42:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_43:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_44:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_45:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_46:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_47:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_48:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_49:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_50:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_51:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_52:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_53:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_54:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_55:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_56:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_57:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_58:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_59:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_60:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_61:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_62:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_63:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_64:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_65:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_66:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_67:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_68:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_69:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_70:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_71:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_72:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_73:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_74:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_75:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_76:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_77:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_78:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_79:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_80:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_81:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_82:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:snv_83:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:opensolaris:*:*:x86:*:*:*:*:* (Version <= snv_84)
  • OR cpe:/o:sun:opensolaris:snv_85:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10:*:x86:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:sun:solaris:8::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::sparc:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:6003
    V
    Security Vulnerability in the X Inter Client Exchange Library (libICE) Shipped With Solaris May Allow a Denial of Service (DoS)
    2009-02-16
    BACK
    sun opensolaris snv_01
    sun opensolaris snv_02
    sun opensolaris snv_03
    sun opensolaris snv_04
    sun opensolaris snv_05
    sun opensolaris snv_06
    sun opensolaris snv_07
    sun opensolaris snv_08
    sun opensolaris snv_09
    sun opensolaris snv_10
    sun opensolaris snv_11
    sun opensolaris snv_12
    sun opensolaris snv_13
    sun opensolaris snv_14
    sun opensolaris snv_15
    sun opensolaris snv_16
    sun opensolaris snv_17
    sun opensolaris snv_18
    sun opensolaris snv_19
    sun opensolaris snv_20
    sun opensolaris snv_21
    sun opensolaris snv_22
    sun opensolaris snv_23
    sun opensolaris snv_24
    sun opensolaris snv_25
    sun opensolaris snv_26
    sun opensolaris snv_27
    sun opensolaris snv_28
    sun opensolaris snv_29
    sun opensolaris snv_30
    sun opensolaris snv_31
    sun opensolaris snv_32
    sun opensolaris snv_33
    sun opensolaris snv_34
    sun opensolaris snv_35
    sun opensolaris snv_36
    sun opensolaris snv_37
    sun opensolaris snv_38
    sun opensolaris snv_39
    sun opensolaris snv_40
    sun opensolaris snv_41
    sun opensolaris snv_42
    sun opensolaris snv_43
    sun opensolaris snv_44
    sun opensolaris snv_45
    sun opensolaris snv_46
    sun opensolaris snv_47
    sun opensolaris snv_48
    sun opensolaris snv_49
    sun opensolaris snv_50
    sun opensolaris snv_51
    sun opensolaris snv_52
    sun opensolaris snv_53
    sun opensolaris snv_54
    sun opensolaris snv_55
    sun opensolaris snv_56
    sun opensolaris snv_57
    sun opensolaris snv_58
    sun opensolaris snv_59
    sun opensolaris snv_60
    sun opensolaris snv_61
    sun opensolaris snv_62
    sun opensolaris snv_63
    sun opensolaris snv_64
    sun opensolaris snv_65
    sun opensolaris snv_66
    sun opensolaris snv_67
    sun opensolaris snv_68
    sun opensolaris snv_69
    sun opensolaris snv_70
    sun opensolaris snv_71
    sun opensolaris snv_72
    sun opensolaris snv_73
    sun opensolaris snv_74
    sun opensolaris snv_75
    sun opensolaris snv_76
    sun opensolaris snv_77
    sun opensolaris snv_78
    sun opensolaris snv_79
    sun opensolaris snv_80
    sun opensolaris snv_81
    sun opensolaris snv_82
    sun opensolaris snv_83
    sun opensolaris *
    sun opensolaris snv_85
    sun solaris 8
    sun solaris 8
    sun solaris 9
    sun solaris 9
    sun solaris 10
    sun solaris 10
    sun solaris 8
    sun solaris 8
    sun solaris 9
    sun solaris 10
    sun solaris 10
    sun solaris 9