Unrated severityNVD Advisory· Published Dec 10, 2008· Updated Jun 16, 2026
CVE-2008-5410
CVE-2008-5410
Description
The PK11_SESSION cache in the OpenSSL PKCS#11 engine in Sun Solaris 10 does not maintain reference counts for operations with asymmetric keys, which allows context-dependent attackers to cause a denial of service (failed cryptographic operations) via unspecified vectors, related to the (1) RSA_sign and (2) RSA_verify functions.
Affected products
4cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*+ 2 more
- cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*
- cpe:2.3:o:sun:solaris:10.0:*:x86:*:*:*:*:*
- (no CPE)range: 10
Patches
Vulnerability mechanics
References
9- secunia.com/advisories/33050nvdPatchVendor Advisory
- sunsolve.sun.com/search/document.donvdPatch
- sunsolve.sun.com/search/document.donvdPatch
- sunsolve.sun.com/search/document.donvdVendor Advisory
- www.securityfocus.com/bid/32671nvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2008/3372nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/47137nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5914nvd
News mentions
0No linked articles in our index yet.