CVE-2004-2414: Low severity Novell NetWare FTP Server vulnerability
Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2414?
CVE-2004-2414 is considered a medium severity vulnerability due to the exposure of sensitive password information.
How do I fix CVE-2004-2414?
To mitigate CVE-2004-2414, it is recommended to avoid using Overlay CDs for installation or upgrade of Novell NetWare 6.5 SP 1.1.
What type of sensitive information is exposed by CVE-2004-2414?
CVE-2004-2414 exposes sensitive password information in the NIOUTPUT.TXT and NI.LOG log files.
Who is affected by CVE-2004-2414?
All local users on a system running Novell NetWare 6.5 SP 1.1 that have accessed the log files are potentially affected by CVE-2004-2414.
What component is primarily involved in CVE-2004-2414?
The primary component involved in CVE-2004-2414 is the OpenSSH implementation included during the custom installation of Novell NetWare 6.5 SP 1.1.