Product: Solaris 9 Operating System Solaris 10 Operating System
There are several vulnerabilities in the Tomcat JSP/Servlet container
which affect Tomcat 4.0 bundled in Solaris 10 and Solaris 9.

These issues may allow a remote or local unprivileged user to cause
a denial of service (DoS), inject arbitrary web script or HTML via
Cross-Site Scripting (XSS) attempts, read arbitrary files and
source code from the server, or obtain the installation path and
other sensitive information.

Additional information regarding these issues is available at:

������ * Apache Tomcat 4.x vulnerabilities:
http://tomcat.apache.org/security-4.html

������ * CVE-2002-1148 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1148

������ * CVE-2002-1394 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1394

������ * CVE-2002-2006 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2006

������ * CVE-2003-0866 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0866

������ * CVE-2005-2090 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2090

������ * CVE-2005-3164 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3164

������ * CVE-2005-3510 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3510

������ * CVE-2006-3835 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3835

������ * CVE-2007-0450 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0450

������ * CVE-2007-1355 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1355

������ * CVE-2007-1358 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1358

������ * CVE-2007-2450 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2450

������ * CVE-2007-5461 at:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5461

State: Resolved
First released: 30-Jun-2008
Permalink | Comments [0]

Product:
State: Workaround
First released: 02-Sep-2008
Permalink | Comments [0]

Product: Solaris 8 Operating System Solaris 9 Operating System Solaris 10 Operating System OpenSolaris

A security vulnerability with system calls in the Solaris Kernel may allow two unprivileged local user processes to establish a covert communication channel bypassing system restrictions such as the multi-level security policy found in Solaris Trusted Extensions or the isolation policy implemented using zones(5) or chroot(2).

State: Resolved
First released: 27-Aug-2008
Permalink | Comments [0]

Product: Solaris 10 Operating System OpenSolaris

A security vulnerability in Solaris 10 related to the sendfilev() system call may allow a user who has the ability to create pages that are hosted on a Solaris 10 system using Apache 2.2.x to create a carefully crafted web page which could cause a system panic resulting in a Denial of Service (DoS) condition.
��
In addition, it may be possible for a local unprivileged user to be able to panic the system with a specially crafted program which calls the sendfile() system call (using either the sendfilev(3EXT) library routine or else directly).

State: Resolved
First released: 06-Aug-2008
Permalink | Comments [0]

Product: Solaris 10 Operating System OpenSolaris

A security vulnerability in the Solaris NFS kernel module on Solaris 10 systems with kernel patches 120011-14 (SPARC) and 120012-14 (x86), may allow a local unprivileged user to cause an NFS server to panic, resulting in a Denial of Service (DoS).

State: Resolved
First released: 22-Aug-2008
Permalink | Comments [0]

Product: Solaris 10 Operating System OpenSolaris

A security vulnerability in the NFS Remote Procedure Calls (RPC) zones implementation may allow a local user with administrative privileges in a non-global zone to intercept and corrupt NFS traffic destined for other non-global zones on the system.�� This may result in a Denial of Service (DoS) to the NFS services in the affected non-global zones.

Sun acknowledges with thanks, Hewitt Associates for reporting this issues.

State: Resolved
First released: 25-Aug-2008
Permalink | Comments [0]

Product:
State: Workaround
First released: 25-Aug-2008
Permalink | Comments [0]

Product:
State: Workaround
First released: 18-Aug-2008
Permalink | Comments [0]

Product: Solaris 10 Operating System

A security vulnerability in the NFSv4 client kernel module may allow a local unprivileged user who cooperates with a remote privileged user on an NFSv4 server to be able to cause all NFSv4 mounts on client systems which have an NFSv4 mount of�� the above NFSv4 server to become unresponsive.�� This is a type of Denial of Service (DoS).

State: Resolved
First released: 18-Aug-2008
Permalink | Comments [0]

Product: Sun Java System Portal Server 7.0 Sun Java System Portal Server 7.1

A Cross Site Scripting (XSS) security vulnerability exists in some of the Portlets bundled with Sun Java System Portal Server that may allow remote users to execute arbitrary JavaScript code in a user's web browser.

State: Resolved
First released: 15-Aug-2008
Permalink | Comments [0]

Product: OpenSolaris

Multiple security vulnerabilities in the Remote Desktop Protocol (RDP) Client (rdesktop.1) may allow remote unprivileged users to execute arbitrary code with the permissions of the local user or lead to a Denial of Service (DoS) if rdesktop is used to connect to an untrusted RDP server.

These issues are described in the following documents:


State: Preliminary
First released: 15-Aug-2008
Permalink | Comments [0]

Product: Sun Java System Web Proxy Server 4.0

A Security vulnerability in the FTP subsystem of Sun Java System Web Proxy Server 4.0 may allow a local or remote unprivileged user to prevent the proxy server from accepting new connections, resulting in a Denial of Service (DoS) to the proxy server.

Sun acknowledges, with thanks, Joxean Koret for bringing this issue to our attention.

State: Resolved
First released: 12-Aug-2008
Permalink | Comments [0]

Product:
State: Resolved
First released: 25-Nov-2003
Permalink | Comments [0]

Product: Solaris 8 Operating System, Solaris 9 Operating System, Solaris 10 Operating System, OpenSolaris

Multiple integer, heap and buffer overflow security vulnerabilities exist in the Render, RECORD, Security, and MIT-SHM Extensions to the Solaris X11 display server (Xorg(1) and Xsun(1)) and the Solaris X11 print server (Xprt(1)).�� These vulnerabilities may allow a local or remote unprivileged user who is authorized (via xhost(1) or xauth(1)) to connect to the X server and execute arbitrary code with root privileges, access arbitrary memory within the X server's address space, or crash the X11 display server process. The ability to crash the X11 display server is a type of Denial of Service (DoS).

These issues are described in the following documents:


State: Workaround
First released: 12-Jun-2008
Permalink | Comments [0]

Product:
State: Workaround
First released: 11-Aug-2008
Permalink | Comments [0]