Affected Systems:
Sun Solaris 9.0 _ x86
Sun Solaris 9.0
Sun Solaris 8.0 _ x86
Sun Solaris 8.0
Description:
Solaris is a commercial UNIX operating system developed and maintained by Sun.
A security vulnerability exists in the IP implementation of Solaris 8/9. Remote non-privileged users may exploit this vulnerability to reduce the performance of the online Solaris system by sending specially crafted IP packets.
On the Solaris system, a large number of forged IP fragments and/or a large number of IP fragments failed to be restructured. For example, run the following command:
% /usr/bin/netstat -s /usr/bin/egrep 'ReasmDuplicates ReasmFails'
|
High ip [v6] ReasmDuplicates and ip [v6] ReasmFails counter values may be displayed.
In addition, the single-processor Solaris 8/9 system shows a significant increase in CPU usage. For example, the vmstat (1 M) 'sy 'column shows the CPU usage time in the kernel.