CVE-2003-1078: High severity Sun SunOS vulnerability
The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Do not run the Solaris ftp client with the -d (debug) flag; disable or avoid use of the -d option so the client does not display the user password on the screen during login.
Solaris ftp client (ftp) debug flag (-d) = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1078?
CVE-2003-1078 is classified as a medium severity vulnerability.
How do I fix CVE-2003-1078?
To mitigate CVE-2003-1078, avoid using the debug (-d) flag when running the FTP client.
Which operating systems are affected by CVE-2003-1078?
CVE-2003-1078 affects Solaris versions 2.6, 7, 8, as well as SunOS versions 5.6, 5.7, and 5.8.
What does CVE-2003-1078 do?
CVE-2003-1078 allows FTP clients with the debug flag enabled to display user passwords on the screen during login.
Is CVE-2003-1078 a remote or local vulnerability?
CVE-2003-1078 is a local vulnerability, as it requires local access to the FTP client with debug mode enabled.