62046vdb entry
http://osvdb.org/62046 CVE-2010-0453
Solaris/Open Solaris UCODE_GET_VERSION IOCTL - Denial of Service
Record summary
CVE-2010-0453 has a selected CVSS score of 4.9; EIP currently links 1 catalogued exploit.
Description
The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODE_GET_VERSION IOCTL, which triggers a NULL pointer dereference in the ucode_get_rev function, related to retrieval of the microcode revision.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSolaris/Open Solaris UCODE_GET_VERSION IOCTL - Denial of ServiceExploitDB exploitby Patroklos ArgyroudisNot analyzed1 file
References
Showing 12 of 1438452Third-party advisory
http://secunia.com/advisories/38452 sunsolve.sun.comConfirmation
http://sunsolve.sun.com/search/document.do?assetkey=1-21-143913-01-1 275910Vendor advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-66-275910-1 1021799Vendor advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021799.1-1 oracle.comConfirmation
http://www.oracle.com/technetwork/topics/security/cpuapr2010-099504.html 20100131 [TKADV2010-001] Oracle Solaris UCODE_GET_VERSION IOCTL Kernel NULL Pointer Dereferencemailing list
http://www.securityfocus.com/archive/1/509276/100/0/threaded 38016vdb entry
http://www.securityfocus.com/bid/38016 trapkit.de
http://www.trapkit.de/advisories/TKADV2010-001.txt TA10-103BThird-party advisory
http://www.us-cert.gov/cas/techalerts/TA10-103B.html ADV-2010-0270vdb entry
http://www.vupen.com/english/advisories/2010/0270 solaris-microcode-dos(55991)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/55991