Sun Kerberos Security Patch May Disclose Kerberos Client Passwords to Local Users
|
|
SecurityTracker Alert ID: 1010530
|
|
SecurityTracker URL: http://securitytracker.com/id?1010530
|
|
CVE Reference: CAN-2004-0653
(Links to External Site)
|
Updated: Jul 14 2004
|
Original Entry Date: Jun 18 2004
|
Impact: Disclosure of authentication information
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Description: A vulnerability was reported in a Sun security patch for Kerberos. A local user may be able to view a user's password in certain cases.
Sun reported that on a Solaris 9 system configured as a kerberos client with patch 112908-12 or 115168-03 installed and any service
using pam_krb5 as an "auth" module, the user's password will be logged in clear text when the pam_krb5 debug feature is enabled
at LOG_DEBUG level.
Patches 112908-12 and 115168-03 have been WITHDRAWN and are no longer available on SunSolve.
Solaris 7
and 8 are not affected by this issue.
|
Impact: The target user's password may be written to a log file in plaintext.
|
Solution: Sun has issued the following fixes:
SPARC Platform
* Solaris 9 with patch 112908-13 or later
x86 Platform
* Solaris 9 with patch 115168-04 or later
|
Vendor URL: sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57587 (Links to External Site)
|
Cause: Access control error
|
Underlying OS: UNIX (Solaris - SunOS)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Fri, 18 Jun 2004 12:03:39 -0400
Subject: http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57587
|
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57587
57587 Solaris 9 Patches 112908-12 and 115168-03 WITHDRAWN, May Cause Passwords to be
Logged as Clear Text on Kerberos Clients 17 Jun 2004
Sun reports that on a Solaris 9 system configured as a kerberos client with patch
112908-12 or 115168-03 installed and any service using pam_krb5 as an "auth" module, the
user's password will be logged in clear text when the pam_krb5 debug feature is enabled at
LOG_DEBUG level.
Patches 112908-12 and 115168-03 have been WITHDRAWN and are no longer available on SunSolve.
Solaris 7 and 8 are not affected by this issue.
Sun has issued the following fixes:
SPARC Platform
* Solaris 9 with patch 112908-13 or later
x86 Platform
* Solaris 9 with patch 115168-04 or later
-----
* Sun Alert ID: 57587
* Synopsis: Solaris 9 Patches 112908-12 and 115168-03 WITHDRAWN, May Cause Passwords
to be Logged as Clear Text on Kerberos Clients
* Category: Security
* Product: Solaris
* BugIDs: 5004688
* Avoidance: Patch, Workaround
* State: Resolved
* Date Released: 17-Jun-2004
* Date Closed: 17-Jun-2004
* Date Modified:
|
|