Ubuntu Remote Login Service Local Information Disclosure Vulnerability
BID:56415
Info
Ubuntu Remote Login Service Local Information Disclosure Vulnerability
| Bugtraq ID: | 56415 |
| Class: | Design Error |
| CVE: |
CVE-2012-0959 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 24 2012 12:00AM |
| Updated: | Oct 24 2012 12:00AM |
| Credit: | Ted Gould |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 |
| Not Vulnerable: | |
Discussion
Ubuntu Remote Login Service Local Information Disclosure Vulnerability
Ubuntu Remote Login Service is prone to a local information-disclosure vulnerability.
Local attackers can exploit this issue to gain access to sensitive information; this may lead to further attacks.
Ubuntu Remote Login Service is prone to a local information-disclosure vulnerability.
Local attackers can exploit this issue to gain access to sensitive information; this may lead to further attacks.
Exploit / POC
Ubuntu Remote Login Service Local Information Disclosure Vulnerability
Attackers require local interactive access to an affected computer to exploit this issue.
Attackers require local interactive access to an affected computer to exploit this issue.
Solution / Fix
Ubuntu Remote Login Service Local Information Disclosure Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Ubuntu Remote Login Service Local Information Disclosure Vulnerability
References:
References:
- Remote Login Service stores servers from previous user (Ted Gould )
- Ubuntu Homepage (Ubuntu)