Oracle Solaris CVE-2011-0412 Password Hash Local Information Disclosure Weakness
BID:47171
Info
Oracle Solaris CVE-2011-0412 Password Hash Local Information Disclosure Weakness
| Bugtraq ID: | 47171 |
| Class: | Unknown |
| CVE: |
CVE-2011-0412 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 05 2011 12:00AM |
| Updated: | Apr 19 2011 08:04PM |
| Credit: | Michael Rutkowski of Duer Advanced Technology and Aerospace, Inc (DATA) |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc |
| Not Vulnerable: | |
Discussion
Oracle Solaris CVE-2011-0412 Password Hash Local Information Disclosure Weakness
Oracle Solaris is prone to a local information-disclosure weakness that affects back-out patch files.
Successful exploits allow local attackers to obtain password hashes for the root account and other accounts. Attackers may employ brute-force techniques on the hashes to obtain passwords.
Oracle Solaris is prone to a local information-disclosure weakness that affects back-out patch files.
Successful exploits allow local attackers to obtain password hashes for the root account and other accounts. Attackers may employ brute-force techniques on the hashes to obtain passwords.
Exploit / POC
Oracle Solaris CVE-2011-0412 Password Hash Local Information Disclosure Weakness
Attackers require local interactive access to an affected computer to exploit this issue.
Attackers require local interactive access to an affected computer to exploit this issue.
Solution / Fix
Oracle Solaris CVE-2011-0412 Password Hash Local Information Disclosure Weakness
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle Solaris CVE-2011-0412 Password Hash Local Information Disclosure Weakness
References:
References:
- Solaris Homepage (Sun Microsystems)
- Oracle Critical Patch Update Advisory - April 2011 (Oracle)
- VU#648244 Oracle Solaris 10 password hashes leaked through back-out patch files (US-CERT)