CVE-2004-2579: High severity Novell iChain vulnerability
Published Dec 31, 2004
·Updated
ACLCHECK module in Novell iChain 2.3 allows attackers to bypass access control rules of an unspecified component via an unspecified attack vector involving a string that contains escape sequences represented with "overlong UTF-8 encoding."
Affected Software
1 affected component
Novell iChain=2.3
Remediation
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Nov 29, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2579?
CVE-2004-2579 is considered a significant security vulnerability as it allows attackers to bypass access control rules.
2
How do I fix CVE-2004-2579?
To fix CVE-2004-2579, you should apply any available patches for Novell iChain 2.3 and review your access control configurations.
3
What component is affected by CVE-2004-2579?
CVE-2004-2579 affects the ACLCHECK module within Novell iChain 2.3.
4
What type of attack does CVE-2004-2579 involve?
CVE-2004-2579 involves an unspecified attack vector that uses overlong UTF-8 encoding to bypass access controls.
5
Who is affected by CVE-2004-2579?
Organizations using Novell iChain 2.3 are at risk due to CVE-2004-2579.