2.1
CVSSv2

CVE-2011-0412

Published: 19/04/2011 Updated: 17/08/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

sun sunos 5.10

sun sunos 5.8

sun sunos 5.9