Release date:
Updated on:
Affected Systems:
Oracle Solaris 9
Oracle Solaris 11.1
Oracle Solaris 10
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66837
CVE (CAN) ID: CVE-2014-0442
Solaris is a computer operating system developed by Sun Microsystems. It is considered to be one of the derivative versions of UNIX operating systems. Currently, Solaris is a hybrid open-source software.
The Oracle Solaris component has a local security vulnerability. authenticated remote attackers can exploit this vulnerability to affect the confidentiality, integrity, and availability of the affected components. Versions affected by this vulnerability include: 9, 10, and 11.1.
Recommended reading:
Chinese EUC cannot be used after Solaris 11 (x86) is installed
Use VNC-Xvnc in Solaris 10/11 (x86)
Oralce Solaris 11 source code installation Qt 4.8.3
Install Zabbix Agent on Solaris 11
<* Source: Oracle
Link: http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Oracle
------
Oracle has released a Security Bulletin (cpuapr2014-1972952) and patches for this:
Cpuapr2014-1972952: Oracle Critical Patch Update Advisory-specification l 2014
Link: http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html