PT-2004-1740 · Oracle+1 · Solaris+1
Published
2004-07-13
·
Updated
2017-10-11
·
CVE-2004-0653
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Solaris 9 versions with patch 112908-12 or 115168-03
Description
The issue allows local users to obtain other users' passwords by reading log files due to the recording of passwords in plaintext when the debug feature is enabled for pam krb5 as an "auth" module.
Recommendations
For Solaris 9 with patch 112908-12, disable the debug feature for pam krb5 to prevent password logging.
For Solaris 9 with patch 115168-03, disable the debug feature for pam krb5 to prevent password logging.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solaris
Pam Krb5