CVE-2003-0636: High severity Novell iChain vulnerability
Published Aug 2, 2003
·Updated
Novell iChain 2.2 before Support Pack 1 does not properly verify that URL redirects match the DNS name of an accelerator, which allows attackers to redirect URLs to malicious web sites.
Affected Software
1 affected component
Novell iChain=2.2
Remediation
Event History
Aug 2, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 27, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0636?
CVE-2003-0636 is considered critical due to its potential to enable phishing attacks by redirecting users to malicious sites.
2
How do I fix CVE-2003-0636?
To mitigate CVE-2003-0636, upgrade Novell iChain from version 2.2 to Support Pack 1 or later.
3
What are the risks associated with CVE-2003-0636?
The risks of CVE-2003-0636 include exposure to phishing attacks and unauthorized redirection of user traffic.
4
Which versions of Novell iChain are affected by CVE-2003-0636?
CVE-2003-0636 affects Novell iChain version 2.2 prior to Support Pack 1.
5
Is CVE-2003-0636 still relevant today?
Although CVE-2003-0636 is an older vulnerability, it remains relevant for organizations still using unsupported versions of Novell iChain.