Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords.
References
Link | Resource |
---|---|
http://support.novell.com/cgi-bin/search/searchtid.cgi?/2968534.htm | Patch Vendor Advisory |
http://www.securityfocus.com/bid/9934 | Patch |
http://secunia.com/advisories/11188 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15600 |
Configurations
Information
Published : 2004-12-30 21:00
Updated : 2017-07-10 18:31
NVD link : CVE-2004-2414
Mitre link : CVE-2004-2414
JSON object : View
CWE
Products Affected
novell
- netware