Vulnerability Description
The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Solaris | 2.5 |
| Sun | Sunos | - |
References
- http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0016.html
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-27116-1Vendor Advisory
- http://www.securityfocus.com/bid/3457
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7334
- http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0016.html
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-27116-1Vendor Advisory
- http://www.securityfocus.com/bid/3457
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7334
FAQ
What is CVE-2001-1503?
CVE-2001-1503 is a vulnerability with a CVSS score of 2.1 (LOW). The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.
How severe is CVE-2001-1503?
CVE-2001-1503 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1503?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Solaris, Sun Sunos.