PT-2004-1740 · Oracle+1 · Solaris+1
Publicado
2004-07-13
·
Atualizado
2017-10-11
·
CVE-2004-0653
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Solaris 9 versions with patch 112908-12 or 115168-03
Description
The issue allows local users to obtain other users' passwords by reading log files due to the recording of passwords in plaintext when the debug feature is enabled for pam krb5 as an "auth" module.
Recommendations
For Solaris 9 with patch 112908-12, disable the debug feature for pam krb5 to prevent password logging.
For Solaris 9 with patch 115168-03, disable the debug feature for pam krb5 to prevent password logging.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Solaris
Pam Krb5