CVE-2003-1078Sensitive Information Exposure in Solaris

Severity
7.5HIGHNVD
EPSS
0.6%
top 30.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 28
Latest updateApr 29

Description

The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDsun/solaris2.6, 7.0, 8.0+2
NVDsun/sunos5.7, 5.8+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2c3c-9673-r29f: The FTP client for Solaris 22022-04-29
CVEList
CVE-2003-1078: The FTP client for Solaris 22005-02-08

💥Exploits & PoCs

1
Exploit-DB
eXtremail 1.5.x (Linux) - Remote Format Strings2003-07-02

📋Vendor Advisories

1
Red Hat
am-utils: insecure usage of temporary files2008-02-14

📐Framework References

2
CWE
Exposure of Sensitive Information to an Unauthorized Actor
CWE
Insertion of Sensitive Information Into Debugging Code

💬Community

1
Bugzilla
CVE-2008-1078 am-utils: insecure usage of temporary files2008-02-29
CVE-2003-1078 — Sensitive Information Exposure | cvebase