Secunia Security Advisory - Alexander Fichman has reported a weakness in Microsoft Office SharePoint Portal Server 2003, which may disclose sensitive information to malicious, local users on the system.
b7bf18526610a3fba5b6eba2971cb85fd9f800185d5e7516244680376b8f4d78
TITLE:
Microsoft Office SharePoint Portal Server Disclosure of User
Credentials
SECUNIA ADVISORY ID:
SA13409
VERIFY ADVISORY:
http://secunia.com/advisories/13409/
CRITICAL:
Not critical
IMPACT:
Exposure of sensitive information
WHERE:
Local system
SOFTWARE:
Microsoft Office SharePoint Portal Server 2003
http://secunia.com/product/4268/
DESCRIPTION:
Alexander Fichman has reported a weakness in Microsoft Office
SharePoint Portal Server 2003, which may disclose sensitive
information to malicious, local users on the system.
The weakness is caused due to an error when installing SPS components
using a user account with a password containing a leading dash. This
causes the installation to fail and includes the password (without
the leading dash) in an error message, which is saved to
"%windir%\temp\STSADM.log-setup_[date] [time].log".
SOLUTION:
Grant only trusted users access to a affected systems.
Don't use passwords containing a leading dash.
PROVIDED AND/OR DISCOVERED BY:
Alexander Fichman
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------