|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
Multiple Unix versions contain a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an unprivileged user is able to access and read the /dev/kmem device content, which will disclose sensitive information such as passwords or email content information resulting in a loss of confidentiality.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Information Disclosure,
Misconfiguration
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to almost any version of Unix after 1999, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround: make sure /dev/kmem is not world readable
|
|
Products |
|
All Operating Systems
 |
All Versions |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|