Vulnerabilities > CVE-2001-1503 - Unspecified vulnerability in SUN Solaris and Sunos
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN sun
nessus
Summary
The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 16 |
Nessus
NASL family | Misc. |
NASL id | FINGER_SOLARIS_DISCLOSURE.NASL |
description | The remote Solaris finger daemon will return a list of accounts that have never been used when it receives the request : finger |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10788 |
published | 2001-10-22 |
reporter | This script is Copyright (C) 2001-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/10788 |
title | Solaris in.fingerd Unused Accounts Disclosure |
code |
|
References
- http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0016.html
- http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0016.html
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-27116-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-27116-1
- http://www.securityfocus.com/bid/3457
- http://www.securityfocus.com/bid/3457
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7334
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7334