|
|
| |
| Under certain circumstances the command "/usr/bin/finger" can divulge too much user account information, specifically a complete list of all account names on a remote system. |
| |
Credit:
The information has been provided by warning3.
|
| |
Vulnerable systems:
Sparc:
* Solaris 2.4
* Solaris 2.5 without patch 111251-01
* Solaris 2.5.1 without patch 111279-01
* Solaris 2.6 without patch 111236-01
* Solaris 7 without patch 111238-01
* Solaris 8 (pre 07/01) or without patch 111232-01
Intel:
* Solaris 2.4
* Solaris 2.5 without patch 111252-01
* Solaris 2.5.1 without patch 111280-01
* Solaris 2.6 without patch 111237-01
* Solaris 7 without patch 111239-01
* Solaris 8 (pre 07/01) without patch 111233-01
Workaround:
The following T-patches are available through normal support channels for the following releases:
Sparc:
* Solaris 2.4 T-patch T111315-01 estimated official patch release date: June 2001
Intel:
* Solaris 2.4 T-patch T111429-01 estimated official patch release date: June 2001
* Solaris 2.5 T-patch T111252-01, estimated official patch release date: June 2001
Resolution:
This issue is addressed in the following URL:
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=salert%2F27116
Exploit:
Running the following command:
$ finger 'a b c d e f g h'@sunhost
|
|
|