Vulnerability Description
Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Sunos | 5.8 |
Related Weaknesses (CWE)
References
- http://osvdb.org/71646
- http://secunia.com/advisories/44047Vendor Advisory
- http://www.kb.cert.org/vuls/id/648244US Government Resource
- http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html
- http://www.securityfocus.com/bid/47171
- http://www.vupen.com/english/advisories/2011/0882Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66579
- http://osvdb.org/71646
- http://secunia.com/advisories/44047Vendor Advisory
- http://www.kb.cert.org/vuls/id/648244US Government Resource
- http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html
- http://www.securityfocus.com/bid/47171
- http://www.vupen.com/english/advisories/2011/0882Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66579
FAQ
What is CVE-2011-0412?
CVE-2011-0412 is a vulnerability with a CVSS score of 2.1 (LOW). Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute ...
How severe is CVE-2011-0412?
CVE-2011-0412 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-0412?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Sunos.