Red Hat Directory Server Cached Files Password Information Disclosure Vulnerability
BID:42165
Info
Red Hat Directory Server Cached Files Password Information Disclosure Vulnerability
| Bugtraq ID: | 42165 |
| Class: | Design Error |
| CVE: |
CVE-2010-2241 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 03 2010 12:00AM |
| Updated: | Aug 03 2010 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Redhat Directory Server 8 EL 5 Redhat Directory Server 8 EL 4 |
| Not Vulnerable: | |
Discussion
Red Hat Directory Server Cached Files Password Information Disclosure Vulnerability
Red Hat Directory Server is prone to a local information-disclosure vulnerability due to a design error.
Exploiting this issue may allow a local attacker to access sensitive information such as the 'Directory' and 'Administration Server' passwords. Information obtained will aid in further attacks.
Red Hat Directory Server is prone to a local information-disclosure vulnerability due to a design error.
Exploiting this issue may allow a local attacker to access sensitive information such as the 'Directory' and 'Administration Server' passwords. Information obtained will aid in further attacks.
Exploit / POC
Red Hat Directory Server Cached Files Password Information Disclosure Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Red Hat Directory Server Cached Files Password Information Disclosure Vulnerability
Solution:
The vendor released fixes to address this issue. Please see the vendor reference for more information.
Solution:
The vendor released fixes to address this issue. Please see the vendor reference for more information.
References
Red Hat Directory Server Cached Files Password Information Disclosure Vulnerability
References:
References:
- Red Hat Directory Server Homepage (Red Hat)