PT-2006-2035 · Novell · Novell Open Enterprise Server+1

Publicado

2006-03-23

·

Atualizado

2020-02-24

·

CVE-2006-0997

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Novell NetWare version 6.5 Novell Open Enterprise Server (OES)
Description The issue allows remote attackers to read an SSL protected session by sniffing network traffic due to the SSL server implementation permitting encryption with a NULL key, resulting in cleartext communication.
Recommendations For Novell NetWare version 6.5, update the SSL server implementation to disallow encryption with a NULL key. For Novell Open Enterprise Server (OES), update the SSL server implementation to disallow encryption with a NULL key.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0997

Produtos afetados

Novell Netware
Novell Open Enterprise Server