PT-2006-2037 · Novell · Novell Open Enterprise Server+2

Publicado

2006-03-23

·

Atualizado

2020-02-24

·

CVE-2006-0999

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Novell NetWare version 6.5 Novell Open Enterprise Server (OES)
Description The issue allows a client to force the server to use weak encryption, potentially enabling remote attackers to decrypt contents of an SSL protected session. This occurs when a client claims that a weak cipher is necessary for compatibility.
Recommendations For Novell NetWare version 6.5, consider disabling the SSL server implementation in NILE.NLM until a fix is available. For Novell Open Enterprise Server (OES), restrict the use of weak ciphers in the SSL server configuration to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0999

Produtos afetados

Nile.Nlm
Novell Netware
Novell Open Enterprise Server