CVE-2011-0412: Low severity sunos vulnerability
Published Apr 19, 2011
·Updated
Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.
Affected Software
3 affected components
Sun SunOS=5.8
Sun SunOS=5.10
Sun SunOS=5.9
Event History
Apr 19, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0412?
CVE-2011-0412 has a medium severity level due to the potential for local users to access sensitive password hashes.
2
How do I fix CVE-2011-0412?
To mitigate CVE-2011-0412, change the permissions of the back-out patch files to restrict access.
3
Who is affected by CVE-2011-0412?
CVE-2011-0412 affects users of Oracle Solaris 8, 9, and 10 operating systems.
4
What type of attack is possible with CVE-2011-0412?
CVE-2011-0412 allows local users to conduct brute force password guessing attacks.
5
What protections can I implement against CVE-2011-0412?
Implementing stricter file permissions and regularly auditing access to sensitive directories can help protect against CVE-2011-0412.