=====================================================================
                                  CERT-Renater

                       Note d'Information No. 2005/VULN030
_____________________________________________________________________

DATE                      : 13/01/2005

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Solaris 8, Solaris 9.

======================================================================

Sun(sm) Alert Notification

       * Sun Alert ID: 57717
       * Synopsis: SMC Default Configuration GUI Creates User Accounts With
       Blank Password Instead of Locked Account
       * Category: Security
       * Product: Solaris, Solaris Management Console (SMC)
       * BugIDs: 4997883
       * Avoidance: Patch, Workaround
       * State: Resolved
       * Date Released: 10-Jan-2005
       * Date Closed: 10-Jan-2005
       * Date Modified:

1. Impact User accounts created with the Solaris Management Console (SMC)
GUI which are configured for password aging (the shadow(4) fields <min>
and <max> fields will be set) may allow login without specifying a
password.

2. Contributing Factors This issue can occur in the following releases:

SPARC Platform

       * Solaris 8 without patches  113749-02 and  109134-31
       * Solaris 9 without patches  114503-08 and  112945-29

x86 Platform

       * Solaris 8 without patches  113750-02 and  109135-31
       * Solaris 9 without patches  114504-08 and  114193-20

Note: Solaris 7 is not affected by this issue.

3. Symptoms This issue can occur when a user account is created with SMC
(default configuration) with aging fields set and no password supplied.
The user account (when being created) is not prompted for a password.

Solution Summary                                                    Top

4. Relief/Workaround To work around the described issue, always supply a
password while creating user accounts with SMC (locked by default).

5. Resolution This issue is resolved in the following releases:

SPARC Platform

       * Solaris 8 with patches  113749-02 or later and  109134-31 or
       later
       * Solaris 9 with patches  114503-08 or later and  112945-29 or
       later

x86 Platform

       * Solaris 8 with patches  113750-02 or later and  109135-31 or
       later
       * Solaris 9 with patches  114504-08 or later and  114193-20 or
       later

Note: Both patches listed for each version of Solaris must be installed to
resolve this issue.

This Sun Alert notification is being provided to you on an "AS IS" basis.
This Sun Alert notification may contain information provided by third
parties. The issues described in this Sun Alert notification may or may
not impact your system(s). Sun makes no representations, warranties, or
guarantees as to the information contained herein. ANY AND ALL WARRANTIES,
EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT,
ARE HEREBY DISCLAIMED. BY ACCESSING THIS DOCUMENT YOU ACKNOWLEDGE THAT SUN
SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE
TO USE THE INFORMATION CONTAINED HEREIN. This Sun Alert notification
contains Sun proprietary and confidential information. It is being
provided to you pursuant to the provisions of your agreement to purchase
services from Sun, or, if you do not have such an agreement, the Sun.com
Terms of Use. This Sun Alert notification may only be used for the
purposes contemplated by these agreements.

Copyright 2000-2005 Sun Microsystems, Inc., 4150 Network Circle, Santa
Clara, CA 95054 U.S.A. All rights reserved.

======================================================================

         =========================================================
         Les serveurs de référence du CERT-Renater
         http://www.urec.fr/securite
         http://www.cru.fr/securite
         http://www.renater.fr
         =========================================================
         + CERT-RENATER          | tel : 01-53-94-20-44          +
         + 151 bd de l'Hopital   | fax : 01-53-94-20-41          +
         + 75013 Paris           | email: certsvp@renater.fr     +
         =========================================================








