Oracle Solaris System Administration (MOSC)

MOSC Banner

Solaris 10 Kerberos Denial of Service Vulnerability CVE-2010-0283 -- patch??

edited Jun 10, 2010 10:07PM in Oracle Solaris System Administration (MOSC) 1 commentAnswered ✓
The vulnerability listed here:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0283 

I can't find anything listed on sun's website.  I'm not running Kerberos, but I have the kerberos packages installed.  Since kerberos is a required core package -- I can't remove it.

Is there any official sun statement or stance on CVE-2010-0283?  I need to get this mitigated immediately.

My security folks are breathing down my neck.

I know that since I'm not running Kerberos, I'm not vulnerable.  But since the libkrb5.so files exist, I can't wiggle out of it in thier eyes.

Thanks!

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center