CVE-2009-3000 describes a denial-of-service vulnerability affecting Sun Solaris 10 and OpenSolaris versions snv_41 through snv_122. This flaw, residing in the sockfs kernel module, allows remote attackers to trigger a system panic by sending specific web-server traffic when Network Cache Accelerator (NCA) logging is enabled, leading to a NULL pointer dereference. With a CVSS score of 7.1, this vulnerability is considered high severity due to its remote attack vector and complete availability impact, though it requires medium attack complexity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
snv_41CPE matchmatch criteria | cpe:2.3:o:sun:opensolaris:snv_41:*:sparc:*:*:*:*:* | ||
snv_42CPE matchmatch criteria | cpe:2.3:o:sun:opensolaris:snv_42:*:sparc:*:*:*:*:* | ||
snv_43CPE matchmatch criteria | cpe:2.3:o:sun:opensolaris:snv_43:*:sparc:*:*:*:*:* | ||
snv_44CPE matchmatch criteria | cpe:2.3:o:sun:opensolaris:snv_44:*:sparc:*:*:*:*:* | ||
snv_45CPE matchmatch criteria | cpe:2.3:o:sun:opensolaris:snv_45:*:sparc:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.