EnGarde WebTool Password Disclosure Vulnerability
BID:8686
Info
EnGarde WebTool Password Disclosure Vulnerability
| Bugtraq ID: | 8686 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 24 2003 12:00AM |
| Updated: | Sep 24 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to "Shawn" <[email protected]>. |
| Vulnerable: |
EnGarde Secure Professional 1.5 EnGarde Secure Community 2.0 |
| Not Vulnerable: | |
Discussion
EnGarde WebTool Password Disclosure Vulnerability
It has been reported that EnGarde WebTool is vulnerable to a password disclosure issue that may allow a local attacker to harvest user passwords. The problem occurs as user authentication credentials are stored in /var/log/userpass.log file. An attacker with root privileges or read access to this file may harvest sensitive user authentication information.
Successful exploitation of this issue may allow an attacker to steal authentication information. This information could be used to launch further attacks.
It has been reported that EnGarde WebTool is vulnerable to a password disclosure issue that may allow a local attacker to harvest user passwords. The problem occurs as user authentication credentials are stored in /var/log/userpass.log file. An attacker with root privileges or read access to this file may harvest sensitive user authentication information.
Successful exploitation of this issue may allow an attacker to steal authentication information. This information could be used to launch further attacks.
Exploit / POC
EnGarde WebTool Password Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
EnGarde WebTool Password Disclosure Vulnerability
Solution:
The vendor has released an advisory ESA-20030924-026 to address this issue. Please see the reference advisory for more information.
Solution:
The vendor has released an advisory ESA-20030924-026 to address this issue. Please see the reference advisory for more information.