First published: Mon Apr 19 2004(Updated: )
The Solaris 9 patches 113579-02 through 113579-05, and 114342-02 through 114342-05, prevent ypserv and ypxfrd from properly restricting access to secure NIS maps, which allows local users to use ypcat or ypmatch to extract the contents of a secure map such as passwd.adjunct.byname.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Patch Manager | =113579-03 | |
Sun Patch Manager | =113579-02 | |
Sun Patch Manager | =114342-04 | |
Sun Patch Manager | =113579-05 | |
Sun Patch Manager | =114342-03 | |
Sun Patch Manager | =114342-02 | |
Sun Patch Manager | =113579-04 | |
Sun Patch Manager | =114342-05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1942 is considered a medium severity vulnerability due to the potential exposure of sensitive information from secure NIS maps.
To mitigate CVE-2004-1942, apply the appropriate patches for Sun Patch Manager versions as listed in the vulnerability report.
CVE-2004-1942 affects Solaris 9 with specific versions of the Sun Patch Manager.
Attackers can exploit CVE-2004-1942 to retrieve sensitive data from secure NIS maps, such as password information.
CVE-2004-1942 is a local vulnerability, allowing local users to exploit the system.