|
|
|
![]() |
Vulnerability Note VU#523710Sun Solaris patches may cause passwords to be logged in clear textOverviewSun Solaris contains a vulnerability in which systems configured as kerberos clients that have specific patches installed may log passwords in clear text.I. DescriptionSun Microsystems released patches 112908-12 and 115168-03 to address issues in kerberos. There is a vulnerability in these patches that may result in user passwords being logged in clear text.According to the Sun Security Alert:
II. ImpactA local user with access to the log files could obtain another user's password.III. SolutionApply a patchSun has issued an advisory which addresses this issue. For more information on patches available for your system, please refer to Sun Security Alert: 57587.
Disable logging of LOG_DEBUG level messages This can be accomplished by the following steps:
2. Send a SIGHUP to syslogd:
Systems Affected
References
This vulnerability was reported by Sun Microsystems Inc. This document was written by Damon Morda.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||