First published: Tue Apr 19 2011(Updated: )
Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =5.8 | |
Sun SunOS | =5.10 | |
Sun SunOS | =5.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0412 has a medium severity level due to the potential for local users to access sensitive password hashes.
To mitigate CVE-2011-0412, change the permissions of the back-out patch files to restrict access.
CVE-2011-0412 affects users of Oracle Solaris 8, 9, and 10 operating systems.
CVE-2011-0412 allows local users to conduct brute force password guessing attacks.
Implementing stricter file permissions and regularly auditing access to sensitive directories can help protect against CVE-2011-0412.