PT-2004-3306 · Novell+1 · Novell Netware+1

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2414

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Novell NetWare version 6.5 SP 1.1
Description: The issue allows local users to potentially obtain sensitive password information. This is due to the inclusion of password details in the NIOUTPUT.TXT and NI.LOG log files when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH.
Recommendations: For Novell NetWare version 6.5 SP 1.1, consider removing or securing access to the NIOUTPUT.TXT and NI.LOG log files to prevent unauthorized access to sensitive password information. As a temporary workaround, restrict access to these log files until a more permanent solution is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2414

Affected Products

Novell Netware
Openssh