Vulnerabilities > CVE-2001-0421 - Unspecified vulnerability in SUN Solaris and Sunos

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
sun
exploit available

Summary

FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.

Exploit-Db

descriptionSolaris 2.6 FTP Core Dump Shadow Password Recovery Vulnerability. CVE-2001-0421. Remote exploit for solaris platform
idEDB-ID:20764
last seen2016-02-02
modified2001-04-17
published2001-04-17
reporterwarning3
sourcehttps://www.exploit-db.com/download/20764/
titleSolaris 2.6 FTP Core Dump Shadow Password Recovery Vulnerability