First published: Tue Jul 13 2004(Updated: )
Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user's passwords by reading log files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Solaris | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.