20010417 Re: SUN SOLARIS 5.6/5.7 FTP Globbing Exploit !mailing list
http://www.securityfocus.com/archive/1/177200 CVE-2001-0421
Solaris 2.6 - FTP Core Dump Shadow Password Recovery
Record summary
CVE-2001-0421 has a selected CVSS score of 6.4; EIP currently links 1 catalogued exploit.
Description
FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSolaris 2.6 - FTP Core Dump Shadow Password RecoveryExploitDB exploitby warning3Not analyzed1 file
References
32601vdb entry
http://www.securityfocus.com/bid/2601 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0421