PT-2001-2588 · Sun · In.Fingerd+2
Published
2001-12-31
·
Updated
2018-10-30
·
CVE-2001-1503
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 2.5 through 8
SunOS versions 5.5 through 5.8
Description
The issue allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host. This is related to the finger daemon (in.fingerd) in the affected operating systems.
Recommendations
For Sun Solaris versions 2.5 through 8, restrict access to the finger daemon to minimize the risk of exploitation.
For SunOS versions 5.5 through 5.8, consider disabling the finger daemon until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun Solaris
Sunos
In.Fingerd