Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x4qg-rgm7-vgvv

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.

Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.

EPSS

Процентиль: 21%
0.00066
Низкий

Связанные уязвимости

nvd
почти 15 лет назад

Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.

EPSS

Процентиль: 21%
0.00066
Низкий