CVE-1999-1215: Medium severity Novell NetWare FTP Server vulnerability
LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Novell NetWare (LOGIN.EXE)from your environment.If LOGIN.EXE is not required, uninstall or remove the LOGIN.EXE binary from affected NetWare 4.0 / 4.01 systems until a vendor-supplied fix or patch is available.
- Configuration
Change filesystem permissions on LOGIN.EXE and its temporary output files so that only trusted administrator accounts can execute or read them; deny execute/read access to unprivileged local users.
Novell NetWare (LOGIN.EXE) file permissions = remove execute/read for non-privileged users - Compensating control
Prevent untrusted local access to systems running Novell NetWare FTP Server (Novell NetWare 4.0 / 4.01). Restrict physical and local console/logon access to trusted administrators only to mitigate local privilege escalation from credentials written to disk.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1215?
CVE-1999-1215 is considered to have a high severity due to its potential to expose sensitive user credentials.
How do I fix CVE-1999-1215?
To fix CVE-1999-1215, users should upgrade to a non-vulnerable version of Novell NetWare, ideally version 4.02 or later.
Who is affected by CVE-1999-1215?
CVE-1999-1215 affects users running Novell NetWare versions 4.0 and 4.01.
What type of data is exposed in CVE-1999-1215?
CVE-1999-1215 exposes user names and passwords by temporarily writing them to disk.
Can CVE-1999-1215 be exploited remotely?
CVE-1999-1215 requires local access to the machine for exploitation.