Secunia Security Advisory - Sun has acknowledged a vulnerability in Sun Update Connection, which can be exploited by malicious, local users to disclose certain sensitive information.
ab3d2ef97d542f4aaf2b1d074251a163d86a3ecc1c99d655f4cb9c58fb4ff614
TITLE:
Sun Solaris Sun Update Connection Proxy Password Disclosure
Vulnerability
SECUNIA ADVISORY ID:
SA17931
VERIFY ADVISORY:
http://secunia.com/advisories/17931/
CRITICAL:
Less critical
IMPACT:
Exposure of sensitive information
WHERE:
Local system
OPERATING SYSTEM:
Sun Solaris 10
http://secunia.com/product/4813/
DESCRIPTION:
Sun has acknowledged a vulnerability in Sun Update Connection, which
can be exploited by malicious, local users to disclose certain
sensitive information.
The vulnerability is caused due to an unspecified error which allows
local users to gain knowledge of the configured web proxy password.
The proxy password is reportedly also visible in the web proxy log
files in the web proxy server.
Successful exploitation requires that Sun Update Connection is
configured to use a web proxy with password authentication enabled.
The vulnerability has been reported in Solaris 10 on both SPARC and
x86 platforms.
SOLUTION:
Apply patches.
-- SPARC Platform --
Solaris 10:
Apply patch 119107-04 or later.
-- x86 Platform --
Solaris 10:
Apply patch 119108-04 or later.
PROVIDED AND/OR DISCOVERED BY:
The vendor credits Nicholas Brealey, Culham Electromagnetics and
Lightning.
ORIGINAL ADVISORY:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102090-1
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------