The Solaris 9 patches 113579-02 through 113579-05, and 114342-02 through 114342-05, prevent ypserv and ypxfrd from properly restricting access to secure NIS maps, which allows local users to use ypcat or ypmatch to extract the contents of a secure map such as passwd.adjunct.byname.
2004-04-19T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sun | patch_manager | 113579-02 | Yes |
Application | sun | patch_manager | 113579-03 | Yes |
Application | sun | patch_manager | 113579-04 | Yes |
Application | sun | patch_manager | 113579-05 | Yes |
Application | sun | patch_manager | 114342-02 | Yes |
Application | sun | patch_manager | 114342-03 | Yes |
Application | sun | patch_manager | 114342-04 | Yes |
Application | sun | patch_manager | 114342-05 | Yes |