PT-2007-4480 · Novell · Novell Modular Authentication Service

Publicado

2007-06-12

·

Atualizado

2017-07-29

·

CVE-2007-3200

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Novell Modular Authentication Service (NMAS) versions 3.1.2 and earlier
Description: The issue allows local users to potentially obtain the admin username and password by reading the NMASINST.LOG file, which logs the invoking command line of NMASINST.
Recommendations: For NMAS versions 3.1.2 and earlier, consider restricting access to the NMASINST.LOG file to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3200

Produtos afetados

Novell Modular Authentication Service