Oracle Solaris 8
Oracle Solaris 8
The Oracle OS Oracle Solaris 8 reached end of service life on Mar 1, 2012 — Oracle OS no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Oracle Solaris 8 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- oracle-solaris
- release
- 8
- product Label
- Oracle Solaris
- release Label
- 8
- codename
- lts
- latest Version
- release Date
- 2000-02-01
- maintained
- source Url
- https://endoflife.date/oracle-solaris
Lifecycle Dates
- End of Service Life
- Mar 1, 2012
- Last OEM Support
- Mar 1, 2009
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Oracle Solaris 8 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Oracle Solaris 8?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Oracle Solaris 8 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Oracle Solaris 8 Support: Frequently Asked Questions
Is the Oracle OS Oracle Solaris 8 still supported?
Oracle OS ended support for the Oracle Solaris 8 on Mar 1, 2012 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Oracle OS Oracle Solaris 8 end of service life (EOSL) date?
Oracle OS lists the end of service life for the Oracle Solaris 8 as Mar 1, 2012.
Can I keep using the Oracle Solaris 8 after its EOSL date?
Yes. EOSL means Oracle OS stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Oracle Solaris 8 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Oracle Solaris 8
20 published CVEs affect the Oracle OS Oracle Solaris 8, including 8 rated critical or high severity. Oracle OS no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2017-3623 | CRITICAL | 10.0 | Apr 24, 2017 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are affected see note. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. While the vulnerability is in Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Solaris. Note: CVE-2017-3623 is assigned for "Ebbisl |
| CVE-2001-0249 | CRITICAL | 9.8 | Jun 18, 2001 | Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings. |
| CVE-2010-3509 | HIGH | 10.0 | Oct 14, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Scheduler. |
| CVE-2002-1337 | HIGH | 10.0 | Mar 7, 2003 | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c. |
| CVE-1999-0046 | HIGH | 10.0 | Feb 6, 1997 | Buffer overflow of rlogin program using TERM environmental variable. |
| CVE-2016-2334 | HIGH | 7.8 | Dec 13, 2016 | Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image. |
| CVE-2011-3537 | HIGH | 7.8 | Oct 18, 2011 | Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel/Filesystem. |
| CVE-2008-4609 | HIGH | 7.1 | Oct 20, 2008 | The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress. |
| CVE-2010-3507 | MEDIUM | 6.6 | Oct 14, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Live Upgrade. |
| CVE-2009-2857 | MEDIUM | 5.5 | Aug 19, 2009 | The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file. |
| CVE-2011-3534 | MEDIUM | 5.0 | Oct 18, 2011 | Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Network Status Monitor (statd). |
| CVE-2010-2386 | MEDIUM | 4.9 | Jul 13, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect availability via unknown vectors related to GigaSwift Ethernet Driver. |
| CVE-2009-3519 | MEDIUM | 4.9 | Oct 1, 2009 | Multiple memory leaks in the IP module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_109, allow local users to cause a denial of service (memory consumption) via vectors related to (1) M_DATA, (2) M_PROTO, (3) M_PCPROTO, and (4) M_SIG STREAMS messages. |
| CVE-1999-0524 | MEDIUM | 4.0 | Aug 1, 1997 | ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. |
| CVE-2010-3576 | LOW | 3.6 | Oct 14, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect integrity and availability, related to the SCSI enclosure services device driver. |
| CVE-2010-2383 | LOW | 3.2 | Jul 13, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect confidentiality and integrity, related to NFS. |
| CVE-2010-2382 | LOW | 3.2 | Jul 13, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via unknown vectors. |
| CVE-2010-2376 | LOW | 3.2 | Jul 13, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via unknown vectors related to Solaris Management Console. |
| CVE-2004-1349 | LOW | 2.1 | Oct 4, 2004 | gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files. |
| CVE-2010-3542 | LOW | 1.9 | Oct 14, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect confidentiality, related to USB. |