CVE-2003-1078
published 2003-02-28CVE-2003-1078: The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.
PriorityP423high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.33%
67.7th percentile
The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | solaris | — | — |
| sun | solaris | — | — |
| sun | solaris | — | — |
| sun | sunos | — | — |
| sun | sunos | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2c3c-9673-r29f: The FTP client for Solaris 2
ghsa_unreviewed·2022-04-29
CVE-2003-1078 [HIGH] GHSA-2c3c-9673-r29f: The FTP client for Solaris 2
The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.
Red Hat
am-utils: insecure usage of temporary files
vendor_redhat·2008-02-14·CVSS 7.2
CVE-2008-1078 [HIGH] am-utils: insecure usage of temporary files
am-utils: insecure usage of temporary files
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.
Statement: The risks associated with fixing this bug are greater than the low severity security risk.We therefore currently have no plans to fix this flaw in Red HatEnterprise Linux.
For more information please see the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=435420
No detection rules found.
CWE
Exposure of Sensitive Information to an Unauthorized Actor
mitre_cwe
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
There are many different kinds of mistakes that introduce information exposures. The severity of the error can range widely, depending on the context in which the product operates, the type of sensitive information that is revealed, and the benefits it may provide to an attacker. Some kinds of sensitive information include: private, personal information, such as personal messages, financial data, health records, geographic location, or contact details system status and environment, such as the operating system and installed packages business secrets and intellectual property network status and confi
CWE
Insertion of Sensitive Information Into Debugging Code
mitre_cwe
CWE-215 Insertion of Sensitive Information Into Debugging Code
CWE-215: Insertion of Sensitive Information Into Debugging Code
The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.
When debugging, it may be necessary to report detailed information to the programmer. However, if the debugging code is not disabled when the product is operating in a production environment, then this sensitive information may be exposed to attackers.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Confidentiality. Impact: Read Application Data.
Detection Methods:
Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source cod
http://secunia.com/advisories/8186/http://sunsolve.sun.com/search/document.do?assetkey=1-26-51081-1http://www.securityfocus.com/bid/6989http://www.securitytracker.com/id?1006195https://exchange.xforce.ibmcloud.com/vulnerabilities/11436http://secunia.com/advisories/8186/http://sunsolve.sun.com/search/document.do?assetkey=1-26-51081-1http://www.securityfocus.com/bid/6989http://www.securitytracker.com/id?1006195https://exchange.xforce.ibmcloud.com/vulnerabilities/11436
2003-02-28
Published