PT-2004-3306 · Novell+1 · Novell Netware+1
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2414
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Novell NetWare version 6.5 SP 1.1
Description:
The issue allows local users to potentially obtain sensitive password information. This is due to the inclusion of password details in the NIOUTPUT.TXT and NI.LOG log files when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH.
Recommendations:
For Novell NetWare version 6.5 SP 1.1, consider removing or securing access to the NIOUTPUT.TXT and NI.LOG log files to prevent unauthorized access to sensitive password information. As a temporary workaround, restrict access to these log files until a more permanent solution is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Novell Netware
Openssh