CVE-2004-2582: Medium severity Novell iChain vulnerability
Published Dec 31, 2004
·Updated
Novell iChain 2.3 includes the build number in the VIA line of the proxy server's HTTP headers, which allows remote attackers to obtain sensitive information.
Affected Software
1 affected component
Novell iChain=2.3
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Nov 29, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2582?
CVE-2004-2582 has a moderate severity rating as it exposes sensitive information that could be leveraged by attackers.
2
How do I fix CVE-2004-2582?
To fix CVE-2004-2582, upgrade to a version of Novell iChain that does not disclose the build number in the HTTP headers.
3
What type of information is exposed by CVE-2004-2582?
CVE-2004-2582 allows attackers to obtain potentially sensitive information regarding the server's build number.
4
Which versions of Novell iChain are affected by CVE-2004-2582?
CVE-2004-2582 specifically affects Novell iChain version 2.3.
5
Can CVE-2004-2582 be exploited remotely?
Yes, CVE-2004-2582 can be exploited remotely since it involves the HTTP headers sent by the proxy server.