Lucene search

K
nvd[email protected]NVD:CVE-2011-0412
HistoryApr 19, 2011 - 7:55 p.m.

CVE-2011-0412

2011-04-1919:55:01
CWE-255
web.nvd.nist.gov
7

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.001

Percentile

25.7%

Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.

Affected configurations

Nvd
Node
sunsunosMatch5.8
OR
sunsunosMatch5.9
OR
sunsunosMatch5.10
VendorProductVersionCPE
sunsunos5.8cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*
sunsunos5.9cpe:2.3:o:sun:sunos:5.9:*:*:*:*:*:*:*
sunsunos5.10cpe:2.3:o:sun:sunos:5.10:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.001

Percentile

25.7%