CVE-2004-0653: Low severity Sun Solaris vulnerability
Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pamkrb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user's passwords by reading log files.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0653?
CVE-2004-0653 is considered a high severity vulnerability due to its potential to expose user passwords.
How do I fix CVE-2004-0653?
To fix CVE-2004-0653, disable the debug feature of the pam_krb5 authentication module or apply the appropriate patches from Oracle.
What versions of Solaris are affected by CVE-2004-0653?
CVE-2004-0653 affects Solaris 9 when configured as a Kerberos client with specific patches applied.
What risks are associated with CVE-2004-0653?
The risk associated with CVE-2004-0653 includes unauthorized access to user passwords, which could lead to further exploitation.
Who is affected by CVE-2004-0653?
Local users on systems running affected versions of Solaris 9 with pam_krb5 enabled may be impacted by CVE-2004-0653.