PT-2006-6933 · Novell · Novell Client+1

Deral Heiland

·

Published

2006-12-05

·

Updated

2018-10-17

·

CVE-2006-6306

CVSS v2.0

1.2

Low

VectorAV:L/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Novell Client versions 4.91 SP2 through 4.91 SP3
Description A format string issue in the Novell Modular Authentication Services (NMAS) component allows users with physical access to read stack and memory contents. This is achieved by using format string specifiers in the Username field of the logon window.
Recommendations For Novell Client versions 4.91 SP2 and 4.91 SP3, consider restricting access to the logon window to minimize the risk of exploitation. Avoid using format string specifiers in the Username field until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6306

Affected Products

Novell Client
Novell Modular Authentication Service