Title: IBM 7094 CTSS System Text Editor Multiple Instance Password File Disclosure
Info
Disclosure
Unknown
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
Multics CTSS on IBM 7094 contains a flaw that may disclose the contents of the password file. The issue occured when multiple instances of the system text editor were invoked, causing the editor to create temporary files with a constant name. This would unexplicably cause the contents of the system CTSS password file to display to any user logging into the system.
Classification
Location:
Local Access Required
Attack Type:
Information Disclosure,
Race Condition
Impact:
Loss of Confidentiality
Solution:
Discontinued Product
Exploit:
Exploit Public
Disclosure:
Uncoordinated Disclosure
Solution
The vendor has discontinued this product and therefore has no patch or upgrade that mitigates this problem. It is recommended that an alternate software package be used in its place.