PT-2004-3306 · Novell+1 · Novell Netware+1

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-2414

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Novell NetWare version 6.5 SP 1.1
Description: The issue allows local users to potentially obtain sensitive password information. This is due to the inclusion of password details in the NIOUTPUT.TXT and NI.LOG log files when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH.
Recommendations: For Novell NetWare version 6.5 SP 1.1, consider removing or securing access to the NIOUTPUT.TXT and NI.LOG log files to prevent unauthorized access to sensitive password information. As a temporary workaround, restrict access to these log files until a more permanent solution is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-2414

Produtos afetados

Novell Netware
Openssh