Note: This is an archival copy of Security Sun Alert 263689 as previously published on http://sunsolve.sun.com.
Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1020726.1.
Article ID : 1020726.1
Article Type : Sun Alerts (SURE)
Last reviewed : 2010-05-20
Audience : PUBLIC
Copyright Notice: Copyright © 2010, Oracle Corporation and/or its affiliates.

This Alert covers CVE-2010-0882 for the Trusted Extensions component of the Solaris and OpenSolaris products.



Category
Security

Release Phase
Resolved

Bug Id
6844213, 6845488, 6845490, 6858545, 6858546, 6865681, 6875540, 6877439, 6878799, 6902320, 6902321, 6911815, 6918300, 6900032

Product
Solaris 10 Operating System
OpenSolaris

Date of Resolved Release
12-Apr-2010

...

1. Impact

This Alert covers CVE-2010-0882 for the Trusted Extensions component of the Solaris and OpenSolaris products.

Please see http://www.oracle.com/technology/deploy/security/alerts.htm
for more information about Critical Patch Updates and Security Alerts.
This publication relates to the CPU for April 2010.


2. Contributing Factors

This issue can occur in the following releases:

SPARC Platform
  • Solaris 10 without patches 119906-15, 122212-36, 120460-16, 120094-25, 122470-03, and 125533-15
  • OpenSolaris based upon builds snv_01 through snv_134
x86 Platform
  • Solaris 10 without patches 119907-15, 122213-36, 120461-16, 120095-25, 122471-03, and 125534-15
  • OpenSolaris based upon builds snv_01 through snv_134
Note 1: Solaris 8 and Solaris 9 are not impacted by this issue.

Note 2: A system is only vulnerable to this issue if Trusted Extensions is turned on. To determine if a system is configured with Trusted Extensions, the following command can be run:
    $ svcs /system/labeld
STATE STIME FMRI
online 07:08:09 svc:/system/labeld:default
If the state is disabled or if the "/system/labeld" service is not listed, then the system is not configured to use Trusted Extensions.

Note 3: OpenSolaris distributions may include additional bug fixes above and beyond the build from which it was derived.  To determine the base build of OpenSolaris, the following command can be used:
    $ uname -v
snv_86
3. Symptoms

4. Workaround

5. Resolution

This issue is addressed in the following releases:

SPARC Platform
  • Solaris 10 with patches 119906-15, 122212-36, 120460-16, 120094-25, 122470-03, and 125533-15 or later
  • OpenSolaris based upon builds snv_135 or later
x86 Platform
  • Solaris 10 with patches 119907-15, 122213-36, 120461-16, 120095-25, 122471-03, and 125534-15 or later
  • OpenSolaris based upon builds snv_135 or later

References

120460-16
120094-25
122470-03
125533-15
120461-16
120095-25
122471-03
125534-15
119906-15
119907-15
122213-36
122212-36





Attachments
This solution has no attachment