CVE-2011-0412
19.04.2011, 19:55
Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.Enginsight
Vendor | Product | Version |
---|---|---|
sun | sunos | 5.8 |
sun | sunos | 5.9 |
sun | sunos | 5.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References