Andy Davis of NGS Secure has discovered a High risk vulnerability in Oracle Solaris. A local attacker can send a malformed USB configuration descriptor via a malicious USB device and trigger a kernel stack overflow, which could potentially result in arbitrary code execution.
2e244e1f7808afb57fa4c7f833f7a8baf74cd735eb3add71bdb930774f307ca4