PT-2004-1740 · Oracle+1 · Solaris+1

Published

2004-07-13

·

Updated

2017-10-11

·

CVE-2004-0653

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Solaris 9 versions with patch 112908-12 or 115168-03
Description The issue allows local users to obtain other users' passwords by reading log files due to the recording of passwords in plaintext when the debug feature is enabled for pam krb5 as an "auth" module.
Recommendations For Solaris 9 with patch 112908-12, disable the debug feature for pam krb5 to prevent password logging. For Solaris 9 with patch 115168-03, disable the debug feature for pam krb5 to prevent password logging.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0653

Affected Products

Solaris
Pam Krb5