First published: Fri Feb 28 2003(Updated: )
The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =5.7 | |
Sun SunOS | =5.8 | |
Oracle Solaris and Zettabyte File System (ZFS) | =7.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =2.6 | |
Oracle Solaris and Zettabyte File System (ZFS) | =8.0 | |
Sun SunOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1078 is classified as a medium severity vulnerability.
To mitigate CVE-2003-1078, avoid using the debug (-d) flag when running the FTP client.
CVE-2003-1078 affects Solaris versions 2.6, 7, 8, as well as SunOS versions 5.6, 5.7, and 5.8.
CVE-2003-1078 allows FTP clients with the debug flag enabled to display user passwords on the screen during login.
CVE-2003-1078 is a local vulnerability, as it requires local access to the FTP client with debug mode enabled.