Sun Microsystems Inc.

Notified:  December 02, 2002 Updated: December 05, 2002



Vendor Statement

Sun confirms that the priocntl(2) vulnerability does affect all currently supported versions of Solaris: Solaris 2.6, 7, 8, and 9 Sun has released a Sun Alert which describes a workaround until patches are available at: http://sunsolve.Sun.COM/pub-cgi/ The Sun Alert will be updated with the patch information once it becomes available. Sun patches are available from:

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.


The CERT/CC has no additional comments at this time.