CVE-2001-1503: Low severity Sun SunOS vulnerability
Published Dec 31, 2001
·Updated
The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.
Affected Software
16 affected components
Sun SunOS=5.5
Sun Solaris=2.5.1
Sun Solaris=2.5
Sun SunOS=5.8
Sun SunOS=5.7
Sun SunOS=5.7
Sun SunOS=5.5
Sun SunOS=5.8
Sun SunOS=5.5.1
Sun Solaris=7.0
Sun SunOS=5.6
Sun SunOS=5.5.1
Sun SunOS=5.6
Sun Solaris=2.6
Sun Solaris=8.0
Sun SunOS
Event History
Dec 31, 2001
CVE Published
05:00 AM
Jun 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1503?
CVE-2001-1503 is classified as a moderate severity vulnerability.
2
How does CVE-2001-1503 affect systems?
CVE-2001-1503 allows remote attackers to enumerate user accounts on affected systems via the finger service.
3
How do I fix CVE-2001-1503?
To fix CVE-2001-1503, it is recommended to disable the finger daemon, in.fingerd, on the affected Solaris systems.
4
What versions of Solaris are affected by CVE-2001-1503?
CVE-2001-1503 affects Sun Solaris versions 2.5 through 8 and SunOS versions 5.5 through 5.8.
5
What is the attack vector for CVE-2001-1503?
The attack vector for CVE-2001-1503 is remote access through the finger protocol.