The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/7334 | vdb entry |
http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0016.html | mailing list |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-27116-1 | vendor advisory |
http://www.securityfocus.com/bid/3457 | vdb entry |