First published: Tue Oct 09 2001(Updated: )
The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain BSM audit files are not present under the FTP root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris and Zettabyte File System (ZFS) | =2.5.1 | |
Sun SunOS | =5.7 | |
Sun SunOS | =5.8 | |
Oracle Solaris and Zettabyte File System (ZFS) | =7.0 | |
Sun SunOS | =5.5.1 | |
Oracle Solaris and Zettabyte File System (ZFS) | =2.6 | |
Oracle Solaris and Zettabyte File System (ZFS) | =8.0 | |
Sun SunOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1414 is considered to have a moderate severity level due to its potential to allow remote attackers to hide their activities.
To fix CVE-2001-1414, you should upgrade to a version of Solaris that logs anonymous FTP access.
CVE-2001-1414 affects Solaris versions 2.5.1, 2.6, 7.0, and 8.0, among others.
No, anonymous FTP logging is not enabled by default in the affected versions of Solaris.
The primary risk of CVE-2001-1414 is that it allows attackers to exploit FTP access without detection, which can lead to unauthorized activities.