First published: Fri Dec 31 2004(Updated: )
Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell NetWare | =6.5-sp1.1a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2414 is considered a medium severity vulnerability due to the exposure of sensitive password information.
To mitigate CVE-2004-2414, it is recommended to avoid using Overlay CDs for installation or upgrade of Novell NetWare 6.5 SP 1.1.
CVE-2004-2414 exposes sensitive password information in the NIOUTPUT.TXT and NI.LOG log files.
All local users on a system running Novell NetWare 6.5 SP 1.1 that have accessed the log files are potentially affected by CVE-2004-2414.
The primary component involved in CVE-2004-2414 is the OpenSSH implementation included during the custom installation of Novell NetWare 6.5 SP 1.1.