SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#855635

Sun Solaris lockd(1M) daemon vulnerable to DoS

Overview

A remotely exploitable denial-of-service vulnerability exists in the Solaris lockd(1M) daemon. Exploitation of this vulnerability may kill the lockd process.

I. Description

Sun Microsystems describes the lockd(1M) daemon as follows:

    The lockd utility is part of the NFS lock manager, which supports record locking operations on NFS files. The lock manager provides two functions:

    • it forwards fcntl(2) locking requests for NFS mounted file systems to the lock manager on the NFS server
    • it generates local file locking operations in response to requests forwarded from lock managers running on NFS client machines
A vulnerability in the lockd(1M) daemon may allow a remote attacker to terminate the lockd(1M) process. A tool to exploit this vulnerability is publicly available.

II. Impact

A remote attacker can terminate the lockd(1M) daemon.

III. Solution

Apply a patch. For more information about the patches, please see Sun Alert Notification 47815.

Systems Affected

VendorStatusDate NotifiedDate Updated
Sun Microsystems Inc.Vulnerable5-Feb-2003

References


http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/47815
http://docs.sun.com/db/doc/805-8067/6j7j82mod?a=view
http://www.iss.net/security_center/static/10394.php
http://online.securityfocus.com/bid/5986

Credit

The CERT/CC thanks Phil Moses of UC San Diego for reporting this vulnerability to us.

This document was written by Ian A Finlay.

Other Information

Date Public:2003-01-02
Date First Published:2003-02-05
Date Last Updated:2003-02-06
CERT Advisory: 
CVE-ID(s):CAN-2002-1228
NVD-ID(s):CAN-2002-1228
US-CERT Technical Alerts: 
Metric:8.10
Document Revision:11

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2003 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader