CVE Vulnerabilities

CVE-2011-0412

Published: Apr 19, 2011 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.

Affected Software

Name Vendor Start Version End Version
Sunos Sun 5.8 (including) 5.8 (including)
Sunos Sun 5.9 (including) 5.9 (including)
Sunos Sun 5.10 (including) 5.10 (including)

References