|
|
|
![]() |
Vulnerability Note VU#290428Sun Solaris Kernel SSL Proxy service is vulnerable to a denial of service conditionOverviewThe Sun Solaris Kernel SSL Proxy service contains a flaw that may allow a remote attacker to cause a denial of service condition.I. DescriptionSun Solaris 10 operating system provides a module called the SSL Kernel Proxy to improve the performance of applications that do SSL packet processing. This module contains an unspecified vulnerability that may allow an unprivileged remote attacker to act as an SSL client to cause the system to crash.Sun states that the following versions are vulnerable:
To disable the Kernel SSL Proxy service, the svcadm(1M) command can be used for each instance of the service: # svcadm disable svc:/network/ssl/proxy:<instance_suffix> To disable and delete the Kernel SSL Proxy service, the ksslcfg(1M) can be used for each instance of the service: # ksslcfg delete [host] <ssl_port>
Referenceshttp://sunsolve.sun.com/search/document.do?assetkey=1-26-102563-1 http://secunia.com/advisories/22136/ http://xforce.iss.net/xforce/xfdb/29185 http://www.securityfocus.com/bid/20224 CreditThis vulnerability was reported by Sun Microsystems in Sun Alert 102563 This document was written by Katie Steiner.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||