PT-2004-3306 · Novell+1 · Novell Netware+1
Publicado
2004-12-31
·
Atualizado
2017-07-11
·
CVE-2004-2414
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Novell NetWare version 6.5 SP 1.1
Description:
The issue allows local users to potentially obtain sensitive password information. This is due to the inclusion of password details in the NIOUTPUT.TXT and NI.LOG log files when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH.
Recommendations:
For Novell NetWare version 6.5 SP 1.1, consider removing or securing access to the NIOUTPUT.TXT and NI.LOG log files to prevent unauthorized access to sensitive password information. As a temporary workaround, restrict access to these log files until a more permanent solution is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Novell Netware
Openssh